CVE-2026-64606: Apache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected
This issue affects Apache Fory: from before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Foryto a version that resolves this vulnerability.Fixed in 1.4.0Patch CVE-2026-64606
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64606?
CVE-2026-64606 has a critical severity rating of 9.8.
How do I fix CVE-2026-64606?
To fix CVE-2026-64606, upgrade Apache Fory to version 1.4.0 or later.
What vulnerability is described by CVE-2026-64606?
CVE-2026-64606 describes a deserialization of untrusted data vulnerability that allows class-registration checks to be bypassed during Java lambda deserialization.
Which versions of Apache Fory are affected by CVE-2026-64606?
Apache Fory versions before 1.4.0 are affected by CVE-2026-64606.
What might be the impact of exploiting CVE-2026-64606?
Exploiting CVE-2026-64606 may allow unauthorized access or manipulation of Java objects due to bypassed class-registration checks.