« Back to list

Alibaba

Alibaba Fastjson: vulnerabilities and CVEs

Alibaba Fastjson has 6 published vulnerabilities, 3 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months3
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-16723Critical (9)0.66%—Jul 23, 2026
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget…
CVE-2026-9497Low (2.1)0.41%—May 25, 2026
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is…
CVE-2025-70974Critical (10)0.77%—Jan 9, 2026
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending…
CVE-2025-34067Critical (10)19%—Jul 2, 2025
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The…
CVE-2022-25845Critical (9.8)19%—Jun 10, 2022
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this…
CVE-2017-18349Critical (9.8)39%—Oct 23, 2018
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Alibaba