CVE-2026-50076: Apache Fory

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes this issue.

Affected products

  • Apache Fory: before 1.1.0 (fixed in 1.1.0)

Published 2026-06-04. Last modified 2026-07-22.