Vulnerability GHSA-pv7h-hx5h-mgfj
High Risk
HIGH RISK
CVSS Score: 8.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
June 11, 2022 at 12:00 AM UTC
Unsafe deserialization in com.alibaba:fastjson
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72
1.2.25 - 1.2.31 and 1.2.49 - 1.2.62 and 1.2.66 - 1.2.72
Summary
Unsafe deserialization in com.alibaba:fastjson
Details
The package com.alibaba:fastjson before 1.2.83 is vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable safeMode.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
2 months ago
fastjson has a remote code execution (RCE) vulnerability
1.2.68 - 1.2.72 and 1.2.83 GHSA-crf3-v9rr-v7hj
1.2.68 - 1.2.72 and 1.2.83 GHSA-crf3-v9rr-v7hj
Critical
8 months ago
FASTJSON Includes Functionality from Untrusted Control Sphere
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
1.1.32 - 1.1.34 and 1.1.42 - 1.1.46 and 1.2.3 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.31 GHSA-jm7w-5684-pvh8
Critical
7 years ago
Improper Input Validation in alilibaba:fastjson
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30 GHSA-xjrr-xv9m-4pw5
1.1.32 - 1.1.34 and 1.1.42 - 1.2.4 and 1.2.8 - 1.2.9 and 1.2.14 - 1.2.16 and 1.2.26 - 1.2.30 GHSA-xjrr-xv9m-4pw5
Impacted packages
Timeline
Published
4 years ago
June 11, 2022 at 12:00 AM UTC
Fixed (1.2.83)
Unknown
Unknown
Last Modified
2 months ago
July 08, 2026 at 06:50 AM UTC