Apache Fory
Class-registration bypass through an auto-admitted SerializedLambda capture interface
- Credit
- Charles Vosburgh — reporter
- Weakness
- CWE-502
- Fixed in
- 1.4.0
Distinct publicly disclosed findings.
Named in a public advisory or CVE record.
Maintainer-published repository advisories.
Public author or reporter credit upstream.
Counting note. Some findings carry both a CVE and a repository GHSA, so identifier totals overlap. The defensible unique total is 21 distinct public vulnerability cases — the identifier counts are not added together. Figures verified against public sources on 2026-09-05.
Each case below links to the independent public advisory record. Credit roles are reproduced exactly as the coordinator published them.
Class-registration bypass through an auto-admitted SerializedLambda capture interface
Schema-controlled values could escape generated validation code
Windows NTFS `.git::$INDEX_ALLOCATION` alias bypass could write into the active gitdir
Sandbox breakout through stacked indirection around dangerous host prototype mutators
Repeated DOCTYPE declarations reset entity-expansion limits, enabling resource exhaustion
Incomplete fix left a sibling range check vulnerable to integer wrap and an out-of-bounds read
The full public record — every identifier, every advisory link — is maintained on SecHive.ai ↗.
SecHive.ai is an operator-driven security research workbench: the operator sets scope and authorization, and every hypothesis is validated, evidenced, and reviewed by a human before anything is disclosed.
SecHive supports this research; it is not presented as the origin of every finding above. Where an advisory credits multiple reporters, that shared attribution is preserved.
Explore SecHive.ai ↗Research is coordinated privately with maintainers and vendors. Public technical material is released only when disclosure status permits, with emphasis on reproducible evidence, remediation validation, and regression prevention.
Additional CVE assignments and reservations remain under coordinated disclosure. Their identifiers and affected products stay private until the responsible coordinator publishes. Where a coordinator has published an advisory but is still withholding a proof of concept, only the public summary appears here.