Skip to content

[GHSA-qwm7-r3rv-3hw8] Deserialization of untrusted data vulnerability that may...#8756

Open
Malayke wants to merge 1 commit into
Malayke/advisory-improvement-8756from
Malayke-GHSA-qwm7-r3rv-3hw8
Open

[GHSA-qwm7-r3rv-3hw8] Deserialization of untrusted data vulnerability that may...#8756
Malayke wants to merge 1 commit into
Malayke/advisory-improvement-8756from
Malayke-GHSA-qwm7-r3rv-3hw8

Conversation

@Malayke

@Malayke Malayke commented Jul 22, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • Source code location
  • Summary

Comments
The affected software names, repository addresses, and affected versions have been supplemented based on the URLs provided in References.

Copilot AI review requested due to automatic review settings July 22, 2026 13:56
@github-actions
github-actions Bot changed the base branch from main to Malayke/advisory-improvement-8756 July 22, 2026 13:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds complete package metadata for the Apache Fory deserialization vulnerability.

Changes:

  • Adds a concise advisory summary.
  • Marks Maven package org.apache.fory:fory-core versions before 1.4.0 as affected.
  • Adds the upstream Apache Fory repository reference.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants