漏洞概述 CVE编号: CVE-2026-71559 漏洞名称: Apache Fury: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata 严重程度: moderate 描述: 在Apache Fury的Go实现中,存在一个反序列化不受信任数据的漏洞。攻击者可以通过提供包含畸形类型元数据的恶意数据,导致服务拒绝(DoS),触发未捕获的panic。 影响范围 受影响版本: Apache Fury 0.16.0 到 1.5.0 其他语言实现: 不受影响 修复方案 建议: 升级到版本1.5.0,该版本已修复此问题。 参考链接 Apache Fury CVE记录 贡献者 报告者: Zhixi "Jace Sun", 独立安全研究员 订阅信息 取消订阅: 发送邮件至 dev-unsubscribe@fury.apache.org 其他命令: 发送邮件至 dev-help@fury.apache.org