Feed/CVE-2026-64606
CVE-2026-64606CRITICALCVSS 9.8

CVE-2026-64606

Published Jul 21, 2026·Updated Jul 27, 2026

NVD Description

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free