Back to overview

CVE-2026-60080

Description
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

Metadata

CVE ID
CVE-2026-60080
State
PUBLISHED
Assigner
apache
Reserved
2026-07-08 11:03 UTC
Published
2026-07-21 10:54 UTC
Last updated
2026-07-21 18:28 UTC
Primary CWE
CWE-416
CWE-416 Use After Free
Vendor / Product
Apache Software Foundation / Apache Fory
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Apache Fory 0.13.0 ≤ 1.3.0
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416 Use After Free
Back to overview