AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71560

CRITICAL · CVSS 9.1 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Fory C++ versions from 0.14.0 to 1.5.0 are vulnerable to an out-of-bounds read during the deserialization of structs with tagged integer fields, which could lead to information disclosure or denial of service. Organizations utilizing affected versions should prioritize upgrading to Apache Fory 1.5.0 to mitigate these risks, especially if their applications involve tagged integer fields. Those not using Apache Fory C++ or tagged integer fields are not impacted by this vulnerability.

CVE
CVE-2026-71560
Severity
CRITICAL
CVSS
9.1
EPSS
0.55%
Apache

Original NVD Description

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)