logo

fastjson RCE Without Gadget or AutoType — CVE-2026-16723

ID: acf6a2a6-5da0-50e4-95df-1ee98d645e2a

STIX ID: report--acf6a2a6-5da0-50e4-95df-1ee98d645e2a

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

## Executive Summary CVE-2026-16723 is a critical (CVSS 9.0) unauthenticated remote code execution vulnerability in fastjson 1.2.68–1.2.83 that bypasses AutoType blocklists and can be exploited in default Spring Boot fat-jar deployments without gadgets; public proof-of-concept code exists and millions of instances may be exposed. Immediate mitigations recommended are enabling fastjson safe mode (-Dfastjson.parser.safeMode=true) and migrating to fastjson2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.