PT-2026-46269 · Unknown · Fory Fory-Core Java Sdk

·

CVE-2026-50076

·

Published

2026-06-04

·

Updated

2026-06-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Fory fory-core versions prior to 1.1.0
Description Deserialization of untrusted data in the Java replace-resolve path on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks. By using crafted Fory serialized data, an attacker can invoke readResolve() and readExternal() hooks present on the classpath.
Recommendations Upgrade to version 1.1.0 or later.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50076
GHSA-8F39-V287-78JF

Affected Products

Fory Fory-Core Java Sdk