apache/fory follows the Apache Software Foundation security process. Please report suspected
vulnerabilities privately to security@apache.org; do not open public
GitHub issues or pull requests for security reports.
User-facing guidance is capability- and runtime-specific:
- Object Serialization runtime guides (each runtime section ends with its own 安全 page)
- Fory JSON 安全
For detailed implementation classification rules for untrusted deserialization, see the Deserialization 安全 Model.