CVE-2026-64609Apache · Fory
Vulnerability data via NVD (ingested)
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-64609product:"Apache Fory"http.html:"Fory"More intel sources (5)
vuln:CVE-2026-64609vulnerabilities.cve_id: CVE-2026-64609CVE-2026-64609CVE-2026-64609"CVE-2026-64609" exploit -site:nvd.nist.gov