{
  "from_raw": "Chaokun Yang <chaokunyang@apache.org>",
  "from": "Chaokun Yang <ch...@apache.org>",
  "gravatar": "5dac1def761b1a642c93c34593f74545",
  "to": "an...@apache.org,\n de...@fory.apache.org",
  "subject": "CVE-2026-60080: Apache Fory: Rust MetaString heap use-after-free",
  "message-id": "<177d8f9f-d6f6-bfc9-ec83-a72d88227489@apache.org>",
  "mid": "l0dwncb0mv2sthy5fgo4cmt13l7vkclq",
  "permalinks": [
    "l0dwncb0mv2sthy5fgo4cmt13l7vkclq",
    "r7d777ba11d897d3747ff6372d6f2a20a395de834456613b3585a5622@<announce.apache.org>"
  ],
  "dbid": "40c5b0ea66b38c7522adebb243dfdf04946c853cb096c70baae052c58f3b7f53",
  "cc": "de...@fory.apache.org",
  "epoch": 1784630976,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/21 10:49:36",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Fory (fory-core) 0.13.0 through 1.3.0\n\nDescription:\n\nUse After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0.\n\n A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure.\n\nUsers are recommended to upgrade to version 1.4.0, which fixes the issue.\n\nCredit:\n\nNguyen Van Hiep (@hypnguyen1209) from MBBank (reporter)\n\nReferences:\n\nhttps://fory.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-60080\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Fory (fory-core) 0.13.0 through 1.3.0\n\nDescription:\n\nUse After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2418,
  "id": "l0dwncb0mv2sthy5fgo4cmt13l7vkclq"
}