CVE-2026-64608: Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip paths
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Fory C++to a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64608?
CVE-2026-64608 has a severity rating of critical with a CVSS score of 9.8.
How do I fix CVE-2026-64608?
To fix CVE-2026-64608, update to the latest version of Apache Fory that addresses this vulnerability.
What impact does CVE-2026-64608 have on users?
CVE-2026-64608 can lead to heap type confusion and out-of-bounds read/write, posing significant security risks to users.
In which software is CVE-2026-64608 found?
CVE-2026-64608 is found in the Apache Fory C++ implementation.
When was CVE-2026-64608 published?
CVE-2026-64608 was published on July 21, 2026.