A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-61622, was discovered in the Apache Fory Python module, specifically affecting pyfory versions 0.12.0 through 0.12.2 and legacy pyfury versions from 0.1.0 through 0.10.3. The flaw arises from the deserialization of untrusted data, where the module's pickle fallback serializer can be triggered by a crafted data stream, leading to the execution of arbitrary code via Python's 'pickle.loads' function. This vulnerability is considered critical, with a CVSS score of 9.8, indicating a high risk of exploitation. Applications that read pyfory serialized data from untrusted sources are particularly at risk, as attackers can exploit this vector to achieve remote code execution on affected systems. The Apache security team has addressed the issue by removing the pickle fallback serializer in pyfory version 0.12.3 and later, effectively mitigating the vulnerability. Security advisories recommend immediate upgrades to the fixed version to prevent exploitation. The vulnerability was publicly disclosed on October 1, 2025, with Apache providing detailed guidance and crediting their security team for the discovery and remediation. The flaw is remotely exploitable, making it a significant concern for organizations using affected versions in production environments. No evidence of active exploitation in the wild has been reported at the time of disclosure, but the technical simplicity of the attack vector increases the urgency for patching. The vulnerability impacts any application that processes serialized data from untrusted sources using the affected pyfory or pyfury versions. Organizations are advised to audit their environments for the presence of vulnerable versions and to apply the recommended updates without delay. The security community has highlighted the risk of deserialization vulnerabilities in Python applications, emphasizing the importance of avoiding unsafe serialization mechanisms like pickle. Apache's response included not only a patch but also updated documentation warning against insecure deserialization practices. The incident underscores the ongoing risks associated with legacy serialization features in widely used open-source libraries. Security researchers have praised the transparency and speed of Apache's response to the issue. The vulnerability has been cataloged in major vulnerability databases, and security vendors have updated their detection signatures accordingly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A high-severity vulnerability record for CVE-2025-61622 was published, identifying Apache Fory/pyfory and describing the Python RCE condition tied to unsafe pickle fallback serialization. This appears to be a follow-on technical cataloging of the same disclosed issue.
A critical remote code execution vulnerability in Apache Fory's Python module, pyfory, was publicly disclosed. The flaw involves an unguarded fallback to Python's pickle serializer, which can allow arbitrary code execution.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.