Heap Type Confusion Vulnerability in Apache Fory C++
CVE-2026-71558

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 August 2026

What is CVE-2026-71558?

A heap type confusion vulnerability has been identified in Apache Fory C++ due to issues with polymorphic smart-pointer deserialization. This flaw allows a maliciously crafted input payload to bypass type compatibility checks, potentially treating an object of an incorrect type as if it were the declared base type. This can lead to undefined behavior, which may result in the denial of service or arbitrary code execution. It is crucial for users to upgrade to Apache Fory version 1.5.0 or later to mitigate this risk. Applications not leveraging polymorphic smart-pointer deserialization functionalities in Apache Fory C++ remain unaffected.

Affected Version(s)

Apache Fory 0.14.0 < 1.5.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhixi "Jace Sun", independent security researcher
.