Impact
The vulnerability is a use‑after‑free in the Rust deserialization logic of Apache Fory. A malicious actor can craft a payload that triggers undefined behavior, potentially causing a process crash or leaking memory contents. This flaw belongs to CWE‑416 and can lead to denial of service or accidental disclosure of sensitive data.
Affected Systems
Affected versions are Apache Fory from 0.13.0 up to and including 1.3.0. Users running any of these releases are susceptible to the issue. The vendor recommends upgrading to version 1.4.0 or later, where the bug has been fixed.
Risk and Exploitability
The CVSS score of 7.3 points to a medium‑to‑high severity vulnerability. The EPSS score is below 1%, indicating a very low probability of exploitation in current public data, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, attack developers can remotely deliver the crafted deserialization payload if the application accepts untrusted data, so the risk remains tangible for exposed services.
OpenCVE Enrichment