{"id":"CVE-2025-70974","details":"Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.","aliases":["GHSA-jm7w-5684-pvh8"],"modified":"2026-08-12T03:51:30.410067043Z","published":"2026-01-09T06:43:23.584Z","database_specific":{"cwe_ids":["CWE-829"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70974.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://cert.360.cn/warning/detail?id=7240aeab581c6dc2c9c5350756079955"},{"type":"WEB","url":"https://github.com/alibaba/fastjson/compare/1.2.47...1.2.48"},{"type":"WEB","url":"https://github.com/vulhub/vulhub/tree/master/fastjson/1.2.47-rce"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-70974.json"},{"type":"WEB","url":"https://www.cnvd.org.cn/flaw/show/CNVD-2019-22238"},{"type":"WEB","url":"https://www.freebuf.com/vuls/208339.html"},{"type":"WEB","url":"https://www.seebug.org/vuldb/ssvid-98020"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-70974"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70974.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70974"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2428203"},{"type":"ARTICLE","url":"https://www.cloudsek.com/blog/androxgh0st-continues-exploitation-operators-compromise-a-us-university-for-hosting-c2-logger"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alibaba/fastjson","events":[{"introduced":"0"},{"fixed":"28da8e194bb7bca71676bb10b9cb343653289de6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.2.48"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["1.2.47","1.2.46","1.2.45","1.2.44","1.2.43","1.2.42","1.2.41","1.2.40","1.2.39","1.2.38","1.2.37","1.1.37","1.2.36","1.2.35","1.2.34","1.2.33","1.2.32","1.2.31","1.2.30","1.2.29","1.2.28","1.2.27","1.2.26","1.2.25","1.2.14","1.2.13","1.2.8","1.1.33","1.2.7","1.2.24","1.2.23","1.2.22","1.2.21","1.2.20","1.2.19","1.2.18","1.2.17","1.2.16","1.2.15","1.2.12","1.2.11_release","1.2.10","1.2.9","1.2.6","1.2.4","1.2.2","1.2.1","1.2.0","1.1.42","1.1.36","1.1.35","1.1.32","1.1.31","1.1.27","1.1.26","1.1.25","1.1.23","1.1.22","1.1.21","1.1.20"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70974.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}