CVE-2026-71560 | Apache Fory up to 1.4.x Struct Deserializer out-of-bounds

SecurityVulns

A vulnerability was found in Apache Fory up to 1.4.x and classified as critical. The affected element is an unknown function of the component Struct Deserializer. The manipulation results in out-of-bounds read.

This vulnerability is cataloged as CVE-2026-71560. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More