What is CVE-2026-64606?
CVE-2026-64606 is a deserialization of untrusted data vulnerability that allows bypassing class-registration checks during Java lambda deserialization, affecting only the lambda-capture class. This issue impacts Apache Fory versions prior to 1.4.0. Users are recommended to upgrade to version 1.4.0, which resolves the issue.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Apache
FAQ2
Which Apache Fory versions are affected by CVE-2026-64606?
This vulnerability affects Apache Fory versions prior to 1.4.0.
What should users do to protect against CVE-2026-64606?
Users are recommended to upgrade to version 1.4.0, which resolves the issue.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.