← Vulnerability feed

Vulnerability record · CVE-2026-64609 · published 21 July 2026

CVE-2026-64609: Apache fory out-of-bounds read vulnerability

Apache · Fory

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

9.1 CVSS 3.1 Critical EPSS 0.78% · top 46.0% CWE-125 · Out-of-bounds read
9.1CVSS 3.1 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
27 Jul 2026Last modified by NVD

Description

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-64609 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-71558Apache fory deserialization of untrusted data vulnerabilityHeap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted…EPSS 0.99%9.8CVE-2026-64606Apache fory deserialization of untrusted data vulnerabilityDeserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lamb…EPSS 0.78%9.8CVE-2026-64608Apache fory deserialization of untrusted data vulnerabilityHeap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip pa…EPSS 0.81%9.8CVE-2026-48207Apache fory deserialization of untrusted data vulnerabilityDeserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…EPSS 0.82%9.8CVE-2025-61622Apache fory deserialization of untrusted data vulnerabilityDeserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows…EPSS 44%9.1CVE-2026-71560Apache fory deserialization of untrusted data vulnerabilityOut-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deseri…EPSS 0.77%9.1CVE-2026-50076Apache fory deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…EPSS 0.74%7.5CVE-2026-71559Apache fory deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying …EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2026-64609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.