CVE-2026-71558Apache · Fory
Vulnerability data via NVD (ingested)
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-71558product:"Apache Fory"http.html:"Fory"More intel sources (5)
vuln:CVE-2026-71558vulnerabilities.cve_id: CVE-2026-71558CVE-2026-71558CVE-2026-71558"CVE-2026-71558" exploit -site:nvd.nist.gov