CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data.
Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Fory fory-core Java SDKto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50076?
CVE-2026-50076 has a critical severity rating of 9.1 on the CVSS scale.
What is the impact of CVE-2026-50076?
CVE-2026-50076 allows a remote attacker to bypass deserialization checks, potentially leading to the execution of arbitrary code.
How do I fix CVE-2026-50076?
To mitigate CVE-2026-50076, update to Apache Fory fory-core Java SDK version 1.1.0 or later.
Which Apache Fory versions are affected by CVE-2026-50076?
CVE-2026-50076 affects all Apache Fory fory-core Java SDK versions prior to 1.1.0.
How can I determine if my system is vulnerable to CVE-2026-50076?
You can determine if your system is vulnerable to CVE-2026-50076 by checking if you are using an affected version of the Apache Fory fory-core Java SDK.