pyfory
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pyforypage 1 of 1
- CVE-2025-61622CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.12.32025-10-01
vulnerable: 0.12.0, 0.12.1, 0.12.2
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized…
- CVE-2026-48207CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.0.02026-05-21
vulnerable: 0.13.0 ... 0.17.0 (8 versions)
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if i…
Check whether pyfory is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pyfory CVEs against the assets you own.
Start Free Scan →