CVE-2026-60080
Description
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0.
A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
References (2)
Source: security@apache.org
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.