Alibaba
Alibaba Fastjson: vulnerabilities and CVEs
Alibaba Fastjson has 6 published vulnerabilities, 3 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months3
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16723 | Critical (9) | 0.66% | — | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget… |
| CVE-2026-9497 | Low (2.1) | 0.41% | — | May 25, 2026 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is… |
| CVE-2025-70974 | Critical (10) | 0.77% | — | Jan 9, 2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending… |
| CVE-2025-34067 | Critical (10) | 19% | — | Jul 2, 2025 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The… |
| CVE-2022-25845 | Critical (9.8) | 19% | — | Jun 10, 2022 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this… |
| CVE-2017-18349 | Critical (9.8) | 39% | — | Oct 23, 2018 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.