Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Stop scrolling: Light’s $299 flip phone and its retro specs could change your life

    July 25, 2026

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Stop scrolling: Light’s $299 flip phone and its retro specs could change your life
    • Malicious sites use JavaScript to build malware in browser memory
    • Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows
    • A single dose reversed autism-like symptoms in adult mice within hours
    • Trump takes swipes at press during White House Correspondents’ Dinner
    • They Gave MAGA a Safe Haven. Now They’re in Retreat.
    • Wealthy gen Xers stand in the way of a Burnham tax on the super-rich | Phillip Inman
    • From Celebration to Escalation: How Trump’s Iran Cease-Fire Collapsed
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 25, 2026Vulnerability / Application Security

    Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

    Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a Spring Boot executable fat-JAR, a network-reachable path that sends attacker-controlled JSON to an affected parser, and SafeMode left at its disabled default. AutoType can remain disabled, and no classpath gadget is required.

    As of July 25, Alibaba had not released a fixed Fastjson 1.x version. Organizations that cannot migrate immediately should enable SafeMode with -Dfastjson.parser.safeMode=true or use com.alibaba:fastjson:1.2.83_noneautotype. Alibaba lists migration to Fastjson2 as the long-term fix.

    Alibaba published its advisory on July 21 following responsible disclosure by Kirill Firsov of FearsOff Cybersecurity. The maintainers described the vulnerability as requiring “no AutoType enablement” and “no classpath gadget.” They verified the chain on Spring Boot 2.x, 3.x, and 4.x with JDK 8, 11, 17, and 21.

    Cybersecurity

    Firsov traced the issue to Fastjson’s type-resolution path. An attacker-controlled @type value can be turned into a class-resource lookup. In a compatible Spring Boot fat-JAR, a crafted nested JAR path can fetch attacker-controlled bytecode. An @JSONType annotation in that resource can then be treated as a trust signal, allowing the class to pass Fastjson’s type checks and load.

    His technical analysis also describes a newer-JDK path that downloads a remote JAR and references it through /proc/self/fd.

    The exploit depends on the Spring Boot executable fat-JAR loader. Alibaba lists plain non-fat JARs, generic uber-JARs, and Tomcat or Jetty WAR deployments as unaffected. Reachable entry points include JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class). Binding input to a fixed class is not sufficient when an object contains an Object or Map field where the payload can be nested.

    ThreatBook said on July 22 that its platform had captured in-the-wild exploitation after adding detection support two days earlier. Its laboratory results were narrower: it reproduced full code execution in a Spring Boot fat-JAR on JDK 8, while its embedded Tomcat test produced only a remote JAR fetch or server-side request forgery.

    Imperva reported activity against financial services, healthcare, computing, retail, and other organizations, primarily in the United States, with smaller volumes in Singapore and Canada. It said browser impersonators generated most requests, while Ruby and Go tools represented about 30% collectively.

    Neither vendor published attack counts, raw requests, execution evidence, named victims, or confirmed compromises. Their reports establish observed exploit activity, not proof of successful code execution against a real-world target or a breach.

    A July 23 CISA-ADP assessment nevertheless marked exploitation as none. The Hacker News confirmed on July 25 that the flaw was absent from CISA’s current Known Exploited Vulnerabilities catalog. The available sources do not explain the mismatch.

    Cybersecurity

    The Hacker News also found no patched Fastjson 1.x artifact in the project’s GitHub tags or Maven Central repository as of July 25. Version 1.2.83 remains the latest standard 1.x release, while 1.2.83_noneautotype remains the available restricted build.

    Organizations should inventory direct and transitive Fastjson dependencies and inspect affected systems for suspicious @type values, nested JAR URLs, unexpected outbound connections, child processes, file changes, and web shells. Fastjson2 is not affected because it does not use the same resource-probing or annotation-based trust path.

    The Hacker News has reached out to Alibaba for clarification on the affected versions and Fastjson 1.x patch plans, and to Imperva for details about the reported exploitation activity. We will update the story with any response.

    Fastjson 1.2.83 was Alibaba’s recommended upgrade for a separate AutoType bypass disclosed in 2022. That final 1.x release now sits inside the affected range for CVE-2026-16723.

    1.x attacks Fastjson Patched RCE targeted Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious sites use JavaScript to build malware in browser memory

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Europol flags 4,340 URLs for removal in ‘The Com’ crackdown

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Stop scrolling: Light’s $299 flip phone and its retro specs could change your life

    July 25, 2026

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026

    A single dose reversed autism-like symptoms in adult mice within hours

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Stop scrolling: Light’s $299 flip phone and its retro specs could change your life

    July 25, 2026

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.