{"id":"GHSA-8f39-v287-78jf","summary":"Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path","details":"Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data.\n\nUsers are recommended to upgrade to version 1.1.0 or later, which fixes this issue.","aliases":["CVE-2026-50076"],"modified":"2026-07-15T22:56:42.607897Z","published":"2026-06-04T18:30:32Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-15T22:32:28Z","nvd_published_at":"2026-06-04T17:16:33Z","cwe_ids":["CWE-502"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50076"},{"type":"WEB","url":"https://fory.apache.org/security"},{"type":"PACKAGE","url":"https://github.com/apache/fory"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/04/4"}],"affected":[{"package":{"name":"org.apache.fory:fory-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.fory/fory-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"versions":["0.11.0","0.11.1","0.11.2","0.12.0","0.12.1","0.12.2","0.12.3","0.13.0","0.13.1","0.13.2","0.14.0","0.14.1","0.15.0","0.16.0","0.17.0","1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-8f39-v287-78jf/GHSA-8f39-v287-78jf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}