CVE-2026-71560

🟠 Łataj w tym tygodniu

Błąd odczytu poza granicami w Apache Fory C++ może prowadzić do ujawnienia informacji.

CVSS
9.1
EPSS
0.5%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.

deserialization dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-08-07 10:16:59 UTC
Ostatnia modyfikacja (NVD)2026-08-08 00:46:13 UTC
Referencje