logo

Critical Defect Exposed: Flaw In Apache Fory Bypasses Deserialization Protections

ID: ad216347-68c5-5603-aff6-a3972efcab76

STIX ID: report--ad216347-68c5-5603-aff6-a3972efcab76

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

Executive summary: A critical PyFory deserialization policy-bypass (CVE-2026-48207, CVSS 9.8) enables remote attackers to execute malicious operations without user interaction when applications run in Python-native mode with strict validation disabled; ReduceSerializer fails to enforce access controls. The flaw affects pyfory versions 0.13.0 through 0.17.0 and is remediated by upgrading to pyfory 1.0.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.