CVE-2026-71559Disclosure(apache / fory)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache fory systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fory

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-07); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fory

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-07: 1Mentions · 2026-08-08: 1Mentions · 2026-08-10: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 108-0708-0808-10
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-071
Disclosure1
2026-08-081
Patch1
2026-08-101
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-71559 Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-71559

    Post summary

    The post discloses CVE-2026-71559, a deserialization-based denial-of-service vulnerability in Apache Fory's Go implementation that can be triggered by crafted data with malformed type metadata.

    00001150
    4.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Apache ❗ CVE-2026-71560 ❗ CVE-2026-71559 ❗ CVE-2026-71558 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-apache-6/ https://t.co/JX6ijCbQ3M

    Post summary

    The post lists three Apache product CVEs and links to an external site for additional information, offering no further details or actionable intelligence.

    00000238
    6.7K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🚨 Apache Fory Go hit by critical deserialization flaw CVE-2026-71559 affects Apache Fory's Go implementation from 0.16.0 before 1.5.0. Crafted serialized data containing malformed type metadata can trigger an uncaught panic and cause denial of service. ✅ Upgrade to 1.5.0. 🔎 Source: Apache / Tenable. #Apache #CVE #CyberSecurity #AppSec #GoLang

    Post summary

    The post highlights a critical deserialization flaw in Apache Fory Go, specifies that malformed serialized data can cause a panic and DoS, and recommends upgrading to 1.5.0 to remediate the vulnerability.

    0000041
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachefory---

Explore more