CyberRota Analysis
AI-GeneratedA heap type confusion vulnerability exists in Apache Fory C++ versions 0.14.0 through 1.5.0, where crafted input can bypass type checks during polymorphic smart-pointer deserialization. This flaw may lead to undefined behavior, potentially resulting in denial of service or arbitrary code execution. Organizations utilizing affected versions should prioritize upgrading to Apache Fory 1.5.0 to mitigate these risks, especially if their applications rely on polymorphic smart-pointer deserialization.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
Related CVEs
Other vulnerabilities affecting the same vendor(s)