Executive brief
Apache Fory, a data processing component, contains a memory management flaw in its data handling logic. An attacker could send a specially crafted data payload to trigger a system crash or potentially gain access to sensitive information stored in the system's memory. This could lead to service interruptions or unauthorized data exposure.
Technical details
A Use After Free (CWE-416) vulnerability exists in the Rust deserialization logic of Apache Fory. The flaw is triggered when the application processes a maliciously crafted Fory payload, leading to memory corruption. An attacker can exploit this to cause undefined behavior, a process crash (Denial of Service), or potential memory disclosure. The vulnerability affects versions 0.13.0 through 1.3.0 and is resolved in version 1.4.0.
Affected products
- Apache Software Foundation Fory 0.13.0 through 1.3.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory