CVE-2026-16723

Published Jul 23, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-16723 identifies a remote code execution (RCE) vulnerability affecting Alibaba's Fastjson library, specifically versions 1.2.68 through 1.2.83. This flaw allows for exploitation under Fastjson's default configuration, meaning it does not require the `AutoType` feature to be enabled or the presence of specific classpath gadgets. The vulnerability is particularly concerning in Spring Boot applications deployed as executable fat-JARs across various JDK versions, including 8, 11, 17, and 21. The vulnerability stems from the library's type-resolution mechanism. An attacker can craft a malicious JSON payload containing a specially designed `@type` value. This crafted input can lead Fastjson to perform resource lookups that allow an attacker to introduce and execute controlled bytecode from a nested JAR path within compatible Spring Boot deployments. The `@JSONType` annotation on the malicious resource then bypasses Fastjson's security checks, facilitating the code execution. Alibaba published an advisory on July 21, 2026, and has recommended enabling SafeMode, using a restricted build, or migrating to Fastjson2 as mitigation, as no patch for the 1.x branch is available.

Description
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Source
alibaba-cna@list.alibaba-inc.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

alibaba-cna@list.alibaba-inc.com
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

9