AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-71559

HIGH · CVSS 7.5 EPSS 0.59%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Go implementation of Apache Fory is vulnerable to a deserialization of untrusted data issue that can lead to a denial of service when an attacker supplies malformed type metadata, resulting in an uncaught panic. This vulnerability impacts versions from 0.16.0 up to, but not including, 1.5.0. Users of Apache Fory in the Go language should prioritize upgrading to version 1.5.0 to mitigate this risk.

CVE
CVE-2026-71559
Severity
HIGH
CVSS
7.5
EPSS
0.59%
Apache

Original NVD Description

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)