GHSA-5hmf-8wx5-4qq3

Suggest an improvement
Source
https://github.com/advisories/GHSA-5hmf-8wx5-4qq3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5hmf-8wx5-4qq3/GHSA-5hmf-8wx5-4qq3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5hmf-8wx5-4qq3
Aliases
Published
2025-09-15T18:31:06Z
Modified
2025-11-05T20:52:11Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Fory Deserialization of Untrusted Data vulnerability
Details

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted data. An attacker can supply a large, specially crafted data payload that, when processed, consumes an excessive amount of CPU resources during the deserialization process. This leads to CPU exhaustion, rendering the application or system using the Apache Fory library unresponsive and unavailable to legitimate users.

Users of Apache Fory are strongly advised to upgrade to version 0.12.2 or later to mitigate this vulnerability. Developers of libraries and applications that depend on Apache Fory should update their dependency requirements to Apache Fory 0.12.2 or later and release new versions of their software.

Database specific
{
    "cwe_ids": [
        "CWE-502"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-09-15T23:31:43Z",
    "nvd_published_at": "2025-09-15T17:15:36Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.apache.fory:fory-core

Package

Name
org.apache.fory:fory-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.fory/fory-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.2

Affected versions

0.*
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-5hmf-8wx5-4qq3/GHSA-5hmf-8wx5-4qq3.json"