Vulnerability GHSA-crf3-v9rr-v7hj

Critical
CRITICAL RISK
CVSS Score: 9.0
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 months ago
July 23, 2026 at 09:32 AM UTC
fastjson has a remote code execution (RCE) vulnerability
1.2.68 - 1.2.72 and 1.2.83
1.2.68 - 1.2.72 and 1.2.83

Summary

fastjson has a remote code execution (RCE) vulnerability

Details

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Impacted packages

Timeline

Published
2 months ago
July 23, 2026 at 09:32 AM UTC
Last Modified
25 days ago
September 10, 2026 at 03:51 AM UTC