A vulnerability was found in Apache Fory 0.14.0/1.3.x and classified as critical. Affected by this issue is some unknown functionality of the component C++ implementation. The manipulation results in out-of-bounds read.

This vulnerability is reported as CVE-2026-64608. The attack can be launched remotely. No exploit exists.