What is CVE-2026-71560?
CVE-2026-71560 is an out-of-bounds read vulnerability in Apache Fory C++ library's deserialization process for structs. It is triggered via crafted tagged integer fields, potentially exposing heap memory. Users should upgrade to version 1.5.0 or later to mitigate the risk.
Azərbaycanca: CVE-2026-71560 Apache Fory C++ kitabxanasında `struct` tipli məlumatların `deserialization` prosesində yaranan `out-of-bounds read` zəifliyidir. Bu zəiflik xüsusi hazırlanmış `tagged integer` sahələri vasitəsilə heap yaddaşdan icazəsiz oxunuşa səbəb ola bilər. Təhlükəsizlik üçün kitabxananı 1.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: Apache
FAQ2
Which version of Apache Fory library is affected by CVE-2026-71560?
Versions below 1.5.0 are affected. Users should upgrade to version 1.5.0 or later to mitigate the risk.
What technique does an attacker use to exploit CVE-2026-71560?
The vulnerability is exploited during the deserialization of structs using crafted tagged integer fields that trigger an out-of-bounds read.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.