What is CVE-2026-60080?
CVE-2026-60080 is a Use After Free vulnerability in the Rust deserialization logic of Apache Fory, affecting versions 0.13.0 through 1.3.0. A crafted payload could cause process crashes or potential memory disclosure. Users are recommended to upgrade to version 1.4.0.
Azərbaycanca: CVE-2026-60080, Apache Fory-nin Rust deserialization məntiqində aşkarlanmış Use After Free zəifliyidir. 0.13.0-dən 1.3.0-dək versiyalar təsirlənir, xüsusi hazırlanmış payload vasitəsilə prosesin çökməsinə və ya potensial yaddaş ifşasına səbəb ola bilər. İstifadəçilərə 1.4.0 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Apache
FAQ2
What software is affected by CVE-2026-60080?
The CVE-2026-60080 vulnerability affects the Rust deserialization logic of Apache Fory.
To which version should users upgrade to fix this Use After Free vulnerability?
Users are recommended to upgrade to Apache Fory version 1.4.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.