{
  "from_raw": "Chaokun Yang <chaokunyang@apache.org>",
  "from": "Chaokun Yang <ch...@apache.org>",
  "gravatar": "5dac1def761b1a642c93c34593f74545",
  "to": "an...@apache.org,\n de...@fory.apache.org",
  "subject": "CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass",
  "message-id": "<4c37dd68-74de-adb0-bac0-5431cadcc102@apache.org>",
  "mid": "oxmf0ggxh99hc572f92oq4yzpwhg4vzj",
  "permalinks": [
    "oxmf0ggxh99hc572f92oq4yzpwhg4vzj",
    "rfef58f99ad88e335529081eb5cd85558eddacb157900d74bd784a533@<announce.apache.org>"
  ],
  "dbid": "f4b45e50fe9621feaa1cd2c012900cfbc5c4517de96b04d68b0b9fc46e394afe",
  "cc": "de...@fory.apache.org",
  "epoch": 1780564108,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/06/04 09:08:28",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Fory (org.apache.fory:fory-core) before 1.1.0\n\nDescription:\n\nDeserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data.\n\nUsers are recommended to upgrade to version 1.1.0 or later, which fixes this issue.\n\nCredit:\n\nVenkatraman Kumar (r3dw0lfsec), Securin (reporter)\n\nReferences:\n\nhttps://fory.apache.org/security\nhttps://fory.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-50076\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Fory (org.apache.fory:fory-core) before 1.1.0\n\nDescription:\n\nDeserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-co",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2661,
  "id": "oxmf0ggxh99hc572f92oq4yzpwhg4vzj"
}