Security · 1h ago
Critical Fastjson RCE Flaw Exploited in Spring Boot Apps
A critical unauthenticated remote code execution vulnerability (CVE-2026-16723) in Fastjson 1.x is being actively exploited. The flaw affects versions 1.2.68 to 1.2.83 and targets Spring Boot fat-jars, allowing attackers to bypass AutoType restrictions. No user interaction is required, and successful exploitation can lead to full server compromise.
Meridian48 take
While the vulnerability is in an end-of-life library, the widespread use of Fastjson in Spring Boot apps means many organizations remain exposed, and patching via migration to Fastjson 2 is urgent.
Read the full reporting
Fastjson 1.x CVE-2026-16723: Unauthenticated RCE Targeting Default Spring Boot Fat-Jars →
DEV Community
fastjsonrce