BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Fastjson flaw lets attackers hijack Spring Boot apps

Critical Fastjson RCE flaw targets Spring Boot apps, no patch available.

  • A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba’s Fastjson library versions 1.2.68 through 1.2.83 when used in Spring Boot applications.
  • Security firms ThreatBook and Imperva report active exploitation targeting financial services, healthcare, and other sectors, primarily in the United States.
  • No patched Fastjson 1.x version is available as of July 25; organizations should enable SafeMode or use the restricted build, while Alibaba recommends migrating to Fastjson2.
  • The exploit requires a Spring Boot fat-JAR and attacker-controlled JSON input but does not need AutoType enablement or a classpath gadget.

On July 25, 2026, security researchers disclosed a critical remote code execution vulnerability in Alibaba‘s Fastjson JSON library that can compromise Spring Boot applications without authentication. Tracked as CVE-2026-16723, the flaw carries a CVSS score of 9.0 and affects Fastjson 1.2.68 through 1.2.83.

- Advertisement -

According to Alibaba’s advisory, the attack chain requires no AutoType enablement and no classpath gadget. The vulnerability was discovered by Kirill Firsov of FearsOff Cybersecurity, who traced the issue to Fastjson’s type-resolution path.

An attacker-controlled @type value can be turned into a class-resource lookup within a Spring Boot fat-JAR, allowing crafted bytecode to be loaded. Firsov’s technical analysis also describes a newer-JDK path that downloads a remote JAR via /proc/self/fd.

ThreatBook reported in-the-wild exploitation after adding detection support, reproducing full code execution on JDK 8. Imperva detected activity against financial services, healthcare, and retail organizations, primarily in the United States, with browser impersonators generating most requests.

Despite these reports, a CISA-ADP assessment marked exploitation as none, and the flaw is absent from CISA’s Known Exploited Vulnerabilities catalog. No patched Fastjson 1.x artifact exists on GitHub or Maven Central as of July 25.

- Advertisement -

Organizations should enable SafeMode with -Dfastjson.parser.safeMode=true or use the restricted 1.2.83_noneautotype build. Alibaba lists migration to Fastjson2 as the long-term fix.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bybit adds Unitree, Moonshot AI to pre-IPO perpetuals

Bybit has launched pre-IPO perpetual contracts for Chinese robotics firm Unitree and AI startup...

Apple and Alibaba team up to launch AI in China

Apple trained its own large language model for the Chinese market with support from...

Trump to Host Crypto CEOs as Bitcoin Stays Flat at $60K

President Donald Trump is expected to attend a White House meeting with top crypto...

Analyst: Bitcoin $1M by 2030 ‘mathematically impossible’

Markus Thielen of 10x Research calls a $1 million Bitcoin by 2030 "mathematically impossible"...

Galaxy lowers CLARITY Act passage odds to 10%

Galaxy Digital now estimates only a 10% chance the CLARITY Act will pass in...

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading