CVE-2026-50076: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache Fory
A critical deserialization vulnerability (CWE-502) exists in Apache Fory fory-core Java SDK versions before 1.1.0. It allows remote attackers to bypass security checks and invoke dangerous Java serialization hooks via crafted serialized data. Upgrading to version 1.1.0 or later addresses this issue.
AI Analysis
Technical Summary
CVE-2026-50076 is a deserialization of untrusted data vulnerability in the Java replace-resolve path of Apache Fory fory-core SDK prior to version 1.1.0. This flaw permits remote attackers to bypass class registration, TypeChecker, and DisallowedList protections, enabling invocation of readResolve/readExternal hooks present on the classpath through maliciously crafted serialized data. This can lead to arbitrary code execution or other high-impact consequences on affected Java/JVM platforms.
Potential Impact
Successful exploitation can result in full confidentiality and integrity compromise (CVSS impact: High on Confidentiality and Integrity, None on Availability). Attackers can bypass critical security checks and execute arbitrary code via deserialization, posing a severe risk to affected systems.
Mitigation Recommendations
Users should upgrade Apache Fory fory-core Java SDK to version 1.1.0 or later, where this vulnerability is fixed. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed in the vendor advisory, but the recommendation to upgrade indicates an official fix is available in 1.1.0.
CVE-2026-50076: CWE-502 Deserialization of Untrusted Data in Apache Software Foundation Apache Fory
Description
A critical deserialization vulnerability (CWE-502) exists in Apache Fory fory-core Java SDK versions before 1.1.0. It allows remote attackers to bypass security checks and invoke dangerous Java serialization hooks via crafted serialized data. Upgrading to version 1.1.0 or later addresses this issue.
CVSS v3.1
Score 9.1critical
Affected software
pkg:maven/org.apache.fory/fory-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50076 is a deserialization of untrusted data vulnerability in the Java replace-resolve path of Apache Fory fory-core SDK prior to version 1.1.0. This flaw permits remote attackers to bypass class registration, TypeChecker, and DisallowedList protections, enabling invocation of readResolve/readExternal hooks present on the classpath through maliciously crafted serialized data. This can lead to arbitrary code execution or other high-impact consequences on affected Java/JVM platforms.
Potential Impact
Successful exploitation can result in full confidentiality and integrity compromise (CVSS impact: High on Confidentiality and Integrity, None on Availability). Attackers can bypass critical security checks and execute arbitrary code via deserialization, posing a severe risk to affected systems.
Mitigation Recommendations
Users should upgrade Apache Fory fory-core Java SDK to version 1.1.0 or later, where this vulnerability is fixed. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed in the vendor advisory, but the recommendation to upgrade indicates an official fix is available in 1.1.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-06-03T12:46:29.360Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a21ac6de29bf47b50b8bc2d
Added to database: 06/04/2026, 16:48:45 UTC
Last enriched: 07/16/2026, 10:50:03 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.