Executive brief
Alibaba fastjson, a widely used Java library for converting Java objects to JSON and vice versa, contains a critical security flaw. This vulnerability allows an attacker to remotely execute malicious code on the server hosting the application. The exploit is particularly dangerous because it works with the library's default settings, potentially leading to full system compromise, data theft, or service disruption.
Technical details
A remote code execution (RCE) vulnerability exists in Alibaba fastjson versions 1.2.68 through 1.2.83 due to improper input validation (CWE-20). The flaw is exploitable via the network without authentication, even in the library's stock default configuration where AutoType is not explicitly enabled. Unlike previous fastjson vulnerabilities, this exploit does not require a specific classpath gadget to achieve code execution. While the attack complexity is rated as High, a successful exploit results in a full scope change, allowing for complete compromise of confidentiality, integrity, and availability. No patched version for the 1.x branch is currently listed in the advisory; users are typically encouraged to migrate to fastjson2 or apply specific security workarounds provided by the vendor.
Affected products
- Alibaba fastjson 1.2.68 - 1.2.83
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
- 2026-08-07: other: Advisory updated