PT-2026-42479 · Apache · Apache Fory
Lide Wen
·
Published
2026-05-21
·
Updated
2026-05-27
·
CVE-2026-48207
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Fory versions prior to 1.0.0
Description
Deserialization of untrusted data in Apache Fory PyFory occurs because the
ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is affected if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes.Recommendations
Upgrade to version 1.0.0 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Fory