Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-release

Apache Fory Deserialization Flaw Lets Attackers Bypass Java Safety Checks

Updated 18d agoFirst seen Jun 4, 20262 sources

Apache disclosed CVE-2026-50076, an important- to high-severity deserialization vulnerability in the Java SDK of Apache Fory that affects org.apache.fory:fory-core versions before 1.1.0. The flaw lies in the Java ReplaceResolverSerializer replace-resolve path, where incomplete verification allows crafted Fory serialized data to bypass class registration requirements, TypeChecker enforcement, and DisallowedList protections during deserialization.

If an application processes untrusted external data streams, a remote attacker can trigger classpath-present readResolve and readExternal hooks on Java/JVM systems, creating a path to unauthorized code execution on backend servers. Apache fixed the issue in version 1.1.0 by adding stricter sanitization checks before deserialization and advised users to upgrade immediately and review deployments that deserialize externally supplied data; the vulnerability was reported by Venkatraman Kumar (r3dw0lfsec) of Securin.

Share:
Apache Fory Deserialization Flaw Lets Attackers Bypass Java Safety Checks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 4, 202619d ago

Apache Fory 1.1.0 released to fix CVE-2026-50076

Apache Fory maintainers released version 1.1.0 or later as the remediation for CVE-2026-50076. The fix adds stricter sanitization checks before deserialization to prevent the ReplaceResolverSerializer bypass.

oss-sec: CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass

Apache discloses CVE-2026-50076 in Apache Fory Java SDK

Apache disclosed CVE-2026-50076, an important-severity deserialization vulnerability in the Java replace-resolve path of fory-core that can let crafted serialized data bypass class registration, TypeChecker, and DisallowedList protections. The issue was credited to Venkatraman Kumar (r3dw0lfsec) of Securin.

oss-sec: CVE-2026-50076: Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Affected products
1 linked
Java Virtual Machine
Organizations
1 linked
Securin
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Apache Fory Deserialization Flaw Lets Attackers Bypass Java Safety Checks | Mallory