← العودة للجدول
CVE-2026-50076
CVE-2026-50076 — Deserialization of Untrusted Data in the Java replace-resolve path in Apache For
📅 2026-06-04
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.1

📋 الوصف الكامل

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes thi

💻 الأنظمة المتأثرة

Apache HTTP Server

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-50076

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.1.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←