← Back

CVE-2026-60080

nvd nist
Published: Jul 21, 2026Modified: Jul 21, 2026

JSON object

Loading...

Description

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

References (2)

Timeline

No history available yet.