Vulnerability GHSA-crf3-v9rr-v7hj
Critical
CRITICAL RISK
CVSS Score: 9.0
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 months ago
July 23, 2026 at 09:32 AM UTC
fastjson has a remote code execution (RCE) vulnerability
1.2.68 - 1.2.72 and 1.2.83
1.2.68 - 1.2.72 and 1.2.83
Summary
fastjson has a remote code execution (RCE) vulnerability
Details
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
8 months ago
FASTJSON Includes Functionality from Untrusted Control Sphere
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
High Risk
4 years ago
Unsafe deserialization in com.alibaba:fastjson
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72 GHSA-pv7h-hx5h-mgfj
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72 GHSA-pv7h-hx5h-mgfj
Critical
7 years ago
Improper Input Validation in alilibaba:fastjson
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30 GHSA-xjrr-xv9m-4pw5
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30 GHSA-xjrr-xv9m-4pw5
Impacted packages
Timeline
Published
2 months ago
July 23, 2026 at 09:32 AM UTC
Last Modified
25 days ago
September 10, 2026 at 03:51 AM UTC