CVE-2026-50076

CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass

Vendor Apache Software Foundation
Product Apache Fory
Weakness CWE-502 · Unsafe deserialization
Published June 4, 2026
Last update June 4, 2026

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.

Key dates

Disclosure timeline

June 4, 2026 CVE published
June 4, 2026 Record updated