PT-2026-42479 · Apache · Apache Fory

Lide Wen

·

Published

2026-05-21

·

Updated

2026-05-27

·

CVE-2026-48207

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Fory versions prior to 1.0.0
Description Deserialization of untrusted data in Apache Fory PyFory occurs because the ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is affected if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes.
Recommendations Upgrade to version 1.0.0 or later.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-48207

Affected Products

Apache Fory