Critical Pre-Auth RCE Flaw Found in Fastjson 1.x; No Patch Available

A critical remote code execution vulnerability, tracked as CVE-2026-16723, has been disclosed in Fastjson versions 1.2.68 through 1.2.83, scoring as high as 9.8 on the CVSS scale. The flaw requires no authentication and exploits a trusted code path in the @JSONType annotation-handling branch, bypassing both AutoType and safeMode protections entirely. An attacker can host a malicious JAR file over plain HTTP and trigger execution simply by sending a crafted JSON payload to any endpoint calling JSON.parseObject(). Unlike previous Fastjson vulnerabilities, this exploit does not rely on known gadget classes or blacklisted type names, making existing defenses ineffective. Alibaba has declared Fastjson 1.x end-of-life and will not issue a patch, directing users to migrate to Fastjson2.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in