apache/fory follows the Apache Software Foundation security process. Please report suspected
vulnerabilities privately to security@apache.org; do not open public
GitHub issues or pull requests for security reports.
User-facing guidance is capability- and runtime-specific:
- Object Serialization runtime guides (each runtime section ends with its own Security page)
- Fory JSON Security
For detailed implementation classification rules for untrusted deserialization, see the Deserialization Security Model.