Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-61622— Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory

EPSS 0.46% · P64
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-61622

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory
Source: NVD (National Vulnerability Database)
Vulnerability Description
Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from 0.1.0 through 0.10.3: allows arbitrary code execution. An application is vulnerable if it reads pyfory serialized data from untrusted sources. An attacker can craft a data stream that selects pickle-fallback serializer during deserialization, leading to the execution of `pickle.loads`, which is vulnerable to remote code execution. Users are recommended to upgrade to pyfory version 0.12.3 or later, which has removed pickle fallback serializer and thus fixes this issue.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
可信数据的反序列化
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Fory 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Fory是Apache基金会的一个序列化框架。 Apache Fory存在安全漏洞,该漏洞源于反序列化不可信数据时使用pickle回退序列化器,可能导致任意代码执行。以下版本受到影响:pyfory 0.12.0版本至0.12.2版本和pyfury 0.1.0版本至0.10.3版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Fory 0.12.0 ~ 0.12.2 -
Apache Software FoundationApache Fory 0.1.0 ~ 0.10.3 -

II. Public POCs for CVE-2025-61622

#POC DescriptionSource LinkShenlong Link
1This PoC demonstrates the Remote Code Execution (RCE) vulnerability in Apache Pyfory (versions 0.12.0-0.12.2 and legacy PyFury 0.1.0-0.10.3) due to insecure pickle fallback deserialization (CVE-2025-61622).https://github.com/fa1consec/cve_2025_61622_pocPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-61622

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-61622

No comments yet


Leave a comment