BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Fastjson flaw lets attackers hijack Spring Boot apps

Critical Fastjson RCE flaw targets Spring Boot apps, no patch available.

  • A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba’s Fastjson library versions 1.2.68 through 1.2.83 when used in Spring Boot applications.
  • Security firms ThreatBook and Imperva report active exploitation targeting financial services, healthcare, and other sectors, primarily in the United States.
  • No patched Fastjson 1.x version is available as of July 25; organizations should enable SafeMode or use the restricted build, while Alibaba recommends migrating to Fastjson2.
  • The exploit requires a Spring Boot fat-JAR and attacker-controlled JSON input but does not need AutoType enablement or a classpath gadget.

On July 25, 2026, security researchers disclosed a critical remote code execution vulnerability in Alibaba‘s Fastjson JSON library that can compromise Spring Boot applications without authentication. Tracked as CVE-2026-16723, the flaw carries a CVSS score of 9.0 and affects Fastjson 1.2.68 through 1.2.83.

- Advertisement -

According to Alibaba’s advisory, the attack chain requires no AutoType enablement and no classpath gadget. The vulnerability was discovered by Kirill Firsov of FearsOff Cybersecurity, who traced the issue to Fastjson’s type-resolution path.

An attacker-controlled @type value can be turned into a class-resource lookup within a Spring Boot fat-JAR, allowing crafted bytecode to be loaded. Firsov’s technical analysis also describes a newer-JDK path that downloads a remote JAR via /proc/self/fd.

ThreatBook reported in-the-wild exploitation after adding detection support, reproducing full code execution on JDK 8. Imperva detected activity against financial services, healthcare, and retail organizations, primarily in the United States, with browser impersonators generating most requests.

Despite these reports, a CISA-ADP assessment marked exploitation as none, and the flaw is absent from CISA’s Known Exploited Vulnerabilities catalog. No patched Fastjson 1.x artifact exists on GitHub or Maven Central as of July 25.

- Advertisement -

Organizations should enable SafeMode with -Dfastjson.parser.safeMode=true or use the restricted 1.2.83_noneautotype build. Alibaba lists migration to Fastjson2 as the long-term fix.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Adobe Patches Critical Magento Flaw Under Active Attack

Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited...

Polish court detains fifth suspect in Zondacrypto fraud case

A Polish court approved pretrial detention for Roman Ż., charged with computer fraud and...

Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises

Bitcoin's correlation with Gold hits a six-year high, signaling its use as a hedge...

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirmed $9.19 million left its blockchain before a network rollback reversed a crypto...

Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.

I bought €100 of PRE about two and a half years ago. I was...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading