A critical vulnerability in FastJson, identified as CVE-2026-16723, is being exploited against organizations in the United States, putting Java applications that process untrusted JSON at immediate risk. This flaw has a CVSS severity score of 9.0 and affects FastJson versions ranging from 1.2.68 to 1.2.83, which is the final release line of FastJson 1.x.0 FastJson is an open-source Java library originally developed by Alibaba for converting Java objects to JSON and for parsing JSON data back into Java objects. The issue was disclosed on July 21, 2026, by FastJson maintainers following research conducted by FearsOff Cybersecurity. It has been confirmed in Spring Boot applications packaged as executable fat JAR files, including...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!