{
  "from_raw": "Chaokun Yang <chaokunyang@apache.org>",
  "from": "Chaokun Yang <ch...@apache.org>",
  "gravatar": "5dac1def761b1a642c93c34593f74545",
  "to": "an...@apache.org,\n de...@fory.apache.org",
  "subject": "CVE-2026-64606: Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interface",
  "message-id": "<fa8b475a-8b3f-0796-83c4-e7975a4182e5@apache.org>",
  "mid": "z4wpcwfcy6htw3s5tdnwl94wls67njct",
  "permalinks": [
    "z4wpcwfcy6htw3s5tdnwl94wls67njct",
    "r5997e309641a3d3b507714d89509fa4ad2e603421eb8b5465db447db@<announce.apache.org>"
  ],
  "dbid": "9ddf328110d085c62030d43cf5e943040cbf60508ef4f070ad685de2b0c6828a",
  "cc": "de...@fory.apache.org",
  "epoch": 1784627889,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/21 09:58:09",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Fory (org.apache.fory:fory-core) 0.5.0 before 1.4.0\n\nDescription:\n\nDeserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected\n\n\nThis issue affects Apache Fory: from before 1.4.0.\n\nUsers are recommended to upgrade to version 1.4.0, which fixes the issue.\n\nCredit:\n\nCharles Vosburgh (reporter)\n\nReferences:\n\nhttps://fory.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-64606\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Fory (org.apache.fory:fory-core) 0.5.0 before 1.4.0\n\nDescription:\n\nDeserialization of untrusted data vulnerability that may allow class-registration c",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2447,
  "id": "z4wpcwfcy6htw3s5tdnwl94wls67njct"
}