GHSA-8f39-v287-78jf
CRITICALCVE-2026-50076Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data.
- Affected
- < 1.1.0
- Fixed in
- 1.1.0
- Weakness
- CWE-502
- Published
- 2026-06-04
- Source
- github