{"id":"GHSA-m5gw-83w2-7749","summary":"Apache Fory PyFory Deserialization of Untrusted Data ","details":"Fory PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes.\n\nThis issue affects Apache Fory: from before 1.0.0.\n\nMitigation: Users of Apache Fory are recommended to upgrade to version 1.0.0 or later, which enforces DeserializationPolicy validation for the affected ReduceSerializer paths and thus fixes this issue.","aliases":["CVE-2026-48207","PYSEC-2026-2984"],"modified":"2026-07-13T16:42:39.987086715Z","published":"2026-05-21T18:33:09Z","database_specific":{"nvd_published_at":"2026-05-21T17:16:21Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-30T21:44:43Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48207"},{"type":"WEB","url":"https://fory.apache.org/security/#cve-2026-48207-pyfory-reduceserializer-deserializationpolicy-bypass"},{"type":"PACKAGE","url":"https://github.com/apache/fory"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/21/10"}],"affected":[{"package":{"name":"pyfory","ecosystem":"PyPI","purl":"pkg:pypi/pyfory"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.13.0"},{"fixed":"1.0.0"}]}],"versions":["0.13.0","0.13.1","0.13.2","0.14.0","0.14.1","0.15.0","0.16.0","0.17.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-m5gw-83w2-7749/GHSA-m5gw-83w2-7749.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}