CVE-2026-48207
Apache Fory allows attackers to execute arbitrary code by deserializing malicious data. The flaw occurs when ReduceSerializer bypasses safety checks, letting attackers inject dangerous objects. Upgrading to version 1.0.0 or later fixes the issue.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Fory, all versions before 1.0.0, used by applications that deserialize data with PyFory Python-native mode and strict mode disabled.
Real-world impact
An attacker could run arbitrary code, steal data, or take control of the affected system.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability enables remote code execution without authentication, with high impact on confidentiality, integrity, and availability.
What to do about it
- 011. Upgrade Apache Fory to version 1.0.0 or later.
NVD-referenced vendor advisory
Timeline
- May 21, 2026 · May 21, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- fory.apache.org/security/vendor advisory
- openwall.com/lists/oss-security/2026/05/…mailing listthird party advisory