SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60080

HIGH · CVSS 7.3 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Apache Fory versions 0.13.0 through 1.3.0 are vulnerable to a Use After Free flaw in the Rust deserialization logic, which can lead to undefined behavior, application crashes, or potential memory disclosure. Organizations utilizing affected versions should prioritize upgrading to version 1.4.0 to mitigate these risks and ensure system integrity.

CVE
CVE-2026-60080
Severity
HIGH
CVSS
7.3
EPSS
0.42%
Apache

Original NVD Description

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)