Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    July 25, 2026

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ShinyHunters data leaks fuel $2,000 sextortion email scam
    • Dango Blockchain to Shut Down, Halt Perp DEX Trading
    • Wisconsin after-school programs lose thousands as child care funding ends
    • ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost
    • Did Trump collapse while trying to get into vehicle?
    • Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration
    • Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO
    • Home Office rejects Palestinian Jerusalemite woman’s UK visa but approves husband’s | Home Office
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 25, 2026Vulnerability / Application Security

    Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

    Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a Spring Boot executable fat-JAR, a network-reachable path that sends attacker-controlled JSON to an affected parser, and SafeMode left at its disabled default. AutoType can remain disabled, and no classpath gadget is required.

    As of July 25, Alibaba had not released a fixed Fastjson 1.x version. Organizations that cannot migrate immediately should enable SafeMode with -Dfastjson.parser.safeMode=true or use com.alibaba:fastjson:1.2.83_noneautotype. Alibaba lists migration to Fastjson2 as the long-term fix.

    Alibaba published its advisory on July 21 following responsible disclosure by Kirill Firsov of FearsOff Cybersecurity. The maintainers described the vulnerability as requiring “no AutoType enablement” and “no classpath gadget.” They verified the chain on Spring Boot 2.x, 3.x, and 4.x with JDK 8, 11, 17, and 21.

    Cybersecurity

    Firsov traced the issue to Fastjson’s type-resolution path. An attacker-controlled @type value can be turned into a class-resource lookup. In a compatible Spring Boot fat-JAR, a crafted nested JAR path can fetch attacker-controlled bytecode. An @JSONType annotation in that resource can then be treated as a trust signal, allowing the class to pass Fastjson’s type checks and load.

    His technical analysis also describes a newer-JDK path that downloads a remote JAR and references it through /proc/self/fd.

    The exploit depends on the Spring Boot executable fat-JAR loader. Alibaba lists plain non-fat JARs, generic uber-JARs, and Tomcat or Jetty WAR deployments as unaffected. Reachable entry points include JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class). Binding input to a fixed class is not sufficient when an object contains an Object or Map field where the payload can be nested.

    ThreatBook said on July 22 that its platform had captured in-the-wild exploitation after adding detection support two days earlier. Its laboratory results were narrower: it reproduced full code execution in a Spring Boot fat-JAR on JDK 8, while its embedded Tomcat test produced only a remote JAR fetch or server-side request forgery.

    Imperva reported activity against financial services, healthcare, computing, retail, and other organizations, primarily in the United States, with smaller volumes in Singapore and Canada. It said browser impersonators generated most requests, while Ruby and Go tools represented about 30% collectively.

    Neither vendor published attack counts, raw requests, execution evidence, named victims, or confirmed compromises. Their reports establish observed exploit activity, not proof of successful code execution against a real-world target or a breach.

    A July 23 CISA-ADP assessment nevertheless marked exploitation as none. The Hacker News confirmed on July 25 that the flaw was absent from CISA’s current Known Exploited Vulnerabilities catalog. The available sources do not explain the mismatch.

    Cybersecurity

    The Hacker News also found no patched Fastjson 1.x artifact in the project’s GitHub tags or Maven Central repository as of July 25. Version 1.2.83 remains the latest standard 1.x release, while 1.2.83_noneautotype remains the available restricted build.

    Organizations should inventory direct and transitive Fastjson dependencies and inspect affected systems for suspicious @type values, nested JAR URLs, unexpected outbound connections, child processes, file changes, and web shells. Fastjson2 is not affected because it does not use the same resource-probing or annotation-based trust path.

    The Hacker News has reached out to Alibaba for clarification on the affected versions and Fastjson 1.x patch plans, and to Imperva for details about the reported exploitation activity. We will update the story with any response.

    Fastjson 1.2.83 was Alibaba’s recommended upgrade for a separate AutoType bypass disclosed in 2022. That final 1.x release now sits inside the affected range for CVE-2026-16723.

    1.x attacks Fastjson Patched RCE targeted Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Europol flags 4,340 URLs for removal in ‘The Com’ crackdown

    Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    July 25, 2026

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026

    ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    July 25, 2026

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.