{
  "from_raw": "Chaokun Yang <chaokunyang@apache.org>",
  "from": "Chaokun Yang <ch...@apache.org>",
  "gravatar": "5dac1def761b1a642c93c34593f74545",
  "to": "an...@apache.org,\n de...@fory.apache.org",
  "subject": "CVE-2026-71559: Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata",
  "message-id": "<9e67b348-ed9c-016b-4661-6ecdd134466d@apache.org>",
  "mid": "5cybfqpx5v0s49lpzkg5dnsjf0opft4j",
  "permalinks": [
    "5cybfqpx5v0s49lpzkg5dnsjf0opft4j",
    "rb2a6f93a78e48eec9afcb3dc41f83ae63182bcb33ca4ce493acacf75@<announce.apache.org>"
  ],
  "dbid": "869546960d4eee266a969f92678000757ab8839ecad50f78fdd71de5cac43d69",
  "cc": "de...@fory.apache.org",
  "epoch": 1786088370,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/07 07:39:30",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache Fory 0.16.0 before 1.5.0\n\nDescription:\n\nDeserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.\n\nThis issue affects Apache Fory: from 0.16.0 before 1.5.0.\u00a0 Users of other language implementations are not affected.\n\nUsers are recommended to upgrade to version 1.5.0, which fixes the issue.\n\nCredit:\n\nZhixi \"Jace Sun\", independent security researcher (reporter)\n\nReferences:\n\nhttps://fory.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-71559\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache Fory 0.16.0 before 1.5.0\n\nDescription:\n\nDeserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to c",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3316,
  "id": "5cybfqpx5v0s49lpzkg5dnsjf0opft4j"
}