{"id":"GHSA-crf3-v9rr-v7hj","summary":"fastjson has a remote code execution (RCE) vulnerability","details":"A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.","aliases":["CVE-2026-16723"],"modified":"2026-09-10T03:51:11.563486204Z","published":"2026-07-23T09:32:01Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-08-07T18:18:20Z","nvd_published_at":"2026-07-23T09:16:26Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16723"},{"type":"PACKAGE","url":"https://github.com/alibaba/fastjson2"},{"type":"WEB","url":"https://github.com/alibaba/fastjson2/wiki/Security-Advisory:-Remote-Code-Execution-in-fastjson-1.2.68%E2%80%931.2.83"}],"affected":[{"package":{"name":"com.alibaba:fastjson","ecosystem":"Maven","purl":"pkg:maven/com.alibaba/fastjson"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.68"},{"last_affected":"1.2.83"}]}],"versions":["1.2.68","1.2.68.sec10","1.2.69","1.2.69_noneautotype","1.2.69_sec11","1.2.69_sec12","1.2.70","1.2.71","1.2.71_noneautotype","1.2.72","1.2.72_noneautotype","1.2.73","1.2.74","1.2.75","1.2.75_noneautotype","1.2.76","1.2.77","1.2.78","1.2.79","1.2.80","1.2.83"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-crf3-v9rr-v7hj/GHSA-crf3-v9rr-v7hj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}