CyberRota Analysis
AI-GeneratedThe Go implementation of Apache Fory is vulnerable to a deserialization of untrusted data issue that can lead to a denial of service when an attacker supplies malformed type metadata, resulting in an uncaught panic. This vulnerability impacts versions from 0.16.0 up to, but not including, 1.5.0. Users of Apache Fory in the Go language should prioritize upgrading to version 1.5.0 to mitigate this risk.
Original NVD Description
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)