{
  "from_raw": "Chaokun Yang <chaokunyang@apache.org>",
  "from": "Chaokun Yang <ch...@apache.org>",
  "gravatar": "5dac1def761b1a642c93c34593f74545",
  "to": "an...@apache.org,\n de...@fory.apache.org",
  "subject": "CVE-2026-48207: Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement",
  "message-id": "<117eff9b-30ce-0b88-e994-af6096bbd84a@apache.org>",
  "mid": "yk20nqjbt0y407o252j2v4tkcjf7tj0l",
  "permalinks": [
    "yk20nqjbt0y407o252j2v4tkcjf7tj0l",
    "r90143e7cc6553c9a4bb5d2f229863d2f1a0ad9a25ffb8dffce3ac184@<announce.apache.org>"
  ],
  "dbid": "263dc2769421a9a49e08873007b320b85897316d3bf00d9693f772f4aef73ede",
  "cc": "de...@fory.apache.org",
  "epoch": 1779367464,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/05/21 12:44:24",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Fory (pyfory) 0.13.0 before 1.0.0\n\nDescription:\n\nDeserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes.\n\nThis issue affects Apache Fory: from before 1.0.0.\n\nMitigation: Users of Apache Fory are recommended to upgrade to version 1.0.0 or later, which enforces DeserializationPolicy validation for the affected ReduceSerializer paths and thus fixes this issue.\n\nCredit:\n\nLide Wen (reporter)\n\nReferences:\n\nhttps://fory.apache.org/security/#cve-2026-48207-pyfory-reduceserializer-deserializationpolicy-bypass\nhttps://fory.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-48207\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Fory (pyfory) 0.13.0 before 1.0.0\n\nDescription:\n\nDeserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docum",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2970,
  "id": "yk20nqjbt0y407o252j2v4tkcjf7tj0l"
}