CVE-2026-64609
Critical · CVSS 9.1- CVSS
- 9.1
- nvd
- EPSS
- 0.34%
- 27th pct
- KEV
- No
- Class
- other
- CWE-125
Description
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
References
Status: profiled · ingested 2026-07-27T18:00:00.000Z