Deserialization Vulnerability in Apache Fory Affects Go Implementation
CVE-2026-71559
Currently unrated
What is CVE-2026-71559?
A deserialization vulnerability in the Go implementation of Apache Fory could enable attackers to execute a denial of service attack by submitting specially crafted data with malformed type metadata. This flaw affects multiple versions from 0.16.0 and is not present in later versions, making it crucial for users to upgrade to version 1.5.0 to remediate this issue. Prompt action is recommended to maintain the integrity and availability of services.
Affected Version(s)
Apache Fory 0.16.0 < 1.5.0