GHSA-crf3-v9rr-v7hjCriticalCVSS 9.0

fastjson has a remote code execution (RCE) vulnerability

Published
July 23, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

🎯 Affected products1

  • maven/com.alibaba:fastjson:>= 1.2.68, <= 1.2.83

🔗 References (3)