What is CVE-2026-71559?
A deserialization of untrusted data vulnerability in the Go version of Apache Fory allows attackers to trigger a denial of service (DoS) by sending crafted data with malformed type metadata, causing an uncaught panic. Users of Apache Fory versions prior to 1.5.0 should upgrade immediately.
Azərbaycanca: Apache Fory-un Go tətbiqində etibarsız məlumatların deserializasiyası zəifliyi (CVE-2026-71559) aşkar edilib. Bu, təcavüzkara xüsusi hazırlanmış məlumatlar göndərərək `panic` yaratmaqla xidmət rəddi (DoS) vəziyyətinə səbəb olmağa imkan verir. Apache Fory 1.5.0-dən əvvəlki versiyaları istifadə edənlər dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Apache
FAQ2
Which programming language implementation of Apache Fory does CVE-2026-71559 affect?
The vulnerability affects the Go implementation of Apache Fory.
What type of attack does CVE-2026-71559 allow?
It allows an attacker to trigger a denial of service (DoS) by sending crafted data that causes an uncaught panic.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.