Junglewise Threat Intelligence

CVE-2026-60080: Apache Fory Use After Free in Rust deserialization logic

CVE-2026-60080 · Severity: info · Published 2026-07-21

Technologies: Apache Software Foundation Fury. Vendors: Apache Software Foundation.

Executive brief

Apache Fory, a data processing component, contains a memory management flaw in its data handling logic. An attacker could send a specially crafted data payload to trigger a system crash or potentially gain access to sensitive information stored in the system's memory. This could lead to service interruptions or unauthorized data exposure.

Technical details

A Use After Free (CWE-416) vulnerability exists in the Rust deserialization logic of Apache Fory. The flaw is triggered when the application processes a maliciously crafted Fory payload, leading to memory corruption. An attacker can exploit this to cause undefined behavior, a process crash (Denial of Service), or potential memory disclosure. The vulnerability affects versions 0.13.0 through 1.3.0 and is resolved in version 1.4.0.

Affected products

  • Apache Software Foundation Fory 0.13.0 through 1.3.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats