# Security Advisory: Remote Code Execution in fastjson 1.2.68–1.2.83 # 安全公告:fastjson 1.2.68–1.2.83 远程代码执行漏洞 > **CVE**:CVE-2026-16723 > **Date / 发布日期**:2026-07-21 (updated / 更新于 2026-07-29) > **Severity / 严重等级**:🔴 Critical / 严重 > **Affected / 影响版本**:fastjson **1.2.68 – 1.2.83** (including 1.2.83, the last 1.x release / 含 1.2.83,即 1.x 最后一个版本) > **Fixed in / 修复版本**:fastjson **1.2.84** ✅ ([release notes](https://github.com/alibaba/fastjson/releases/tag/1.2.84)) > **Not affected / 不影响**:All fastjson2 versions / fastjson2 所有版本(见文末附注 / see note below) --- ## English ### Summary A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's **stock default configuration** — no AutoType enablement required, no classpath gadget required. The only deployment prerequisite is that the target runs as a **Spring Boot executable fat-jar** (i.e., launched via `java -jar xxx.jar`). This is the most common Spring Boot deployment model. Verified end-to-end on Spring Boot 2.x / 3.x / 4.x and JDK 8 / 11 / 17 / 21. ### Affected | Condition | Detail | |-----------|--------| | fastjson version | **1.2.68 – 1.2.83** | | Configuration | AutoType OFF + SafeMode OFF (**stock defaults**) | | Deployment | Spring Boot executable fat-jar | | JDK | 8 / 11 / 17 / 21 verified | | Spring Boot | 2.x / 3.x / 4.x verified | | Entry points | `JSON.parse`, `JSON.parseObject(String)`, `JSON.parseObject(String, Class)` all reachable | > ⚠️ Specifying a target class (e.g., `JSON.parseObject(body, SomeDto.class)`) is **not** a mitigation — attackers can nest payloads inside Object/Map-typed fields of the DTO. ### Not Affected | Condition | Reason | |-----------|--------| | **fastjson ≥ 1.2.84** | Fixed: URL-special type names are rejected before any resource probing or class loading | | **All fastjson2 versions** | Root cause architecturally eliminated | | SafeMode = true | Rejects all `@type` before the vulnerable path is reached | | noneautotype builds | Vulnerable code removed at compile time | | Non-fat-jar deployments | plain `java -jar`, uber-jar, Tomcat/Jetty WAR do not meet the trigger condition | | fastjson ≤ 1.2.60 | Vulnerable code path does not exist | ### fastjson2 Is Not Affected fastjson2 architecturally eliminates the root cause of this vulnerability: - **No resource probing**: The type resolution path contains no `getResourceAsStream` call on user-controlled class names; class loading uses only `ClassLoader.loadClass()` and `Class.forName()` - **No annotation-based trust bypass**: The `@JSONType` annotation is used solely for serialization configuration, not as a trust signal in type resolution - **Allowlist-first model**: Types must match an allowlist or be explicitly approved by an `AutoTypeBeforeHandler`; otherwise they are rejected with no secondary escape path - **autoType disabled by default**: `SupportAutoType` is off by default, deprecated, and carries a security warning fastjson2 users need take no action regarding this vulnerability. ### Remediation #### fastjson 1.x users | Priority | Action | Detail | |----------|--------|--------| | **P0** | **Upgrade to fastjson 1.2.84** | Fixes this vulnerability: `com.alibaba:fastjson:1.2.84` ([release notes](https://github.com/alibaba/fastjson/releases/tag/1.2.84)) | | **P0** | Or enable SafeMode | `-Dfastjson.parser.safeMode=true`, or `ParserConfig.getGlobalInstance().setSafeMode(true)`, or set in `fastjson.properties` | | **P0** | Or switch to a noneautotype build | Maven example: `com.alibaba:fastjson:1.2.83_noneautotype` | | **P1** | Migrate to fastjson2 | Architecturally eliminates this vulnerability; safe under default configuration | The 1.2.84 fix rejects type names containing URL-special characters (`:`/`!`) in `ParserConfig.checkAutoType` and `TypeUtils.loadClass`, so a non-class-name string never reaches the resource probing or the class loader. It also verifies the accept name text after a whitelist hash match, stops an accept prefix from covering `ClassLoader`/`DataSource`/`RowSet` gadget base types, and closes a class-cache path that could return a blacklisted class on a repeated call. #### fastjson2 users No action required for this vulnerability. General security practices: - Do not explicitly enable `JSONReader.Feature.SupportAutoType` (deprecated) - If autoType capability is genuinely needed, use `ContextAutoTypeBeforeHandler` with a strict allowlist ### Acknowledgements We thank Kirill Firsov of FearsOff Cybersecurity for discovering and responsibly disclosing this vulnerability. --- ## 中文 ### 概述 fastjson 1.2.68 至 1.2.83 存在一条远程代码执行(RCE)漏洞。该漏洞在 fastjson 的**默认配置**下即可触发——无需开启 AutoType,无需 classpath 上存在任何 gadget 类。 唯一的部署前置条件是目标运行在 **Spring Boot 可执行 fat-jar** 模式下(即通过 `java -jar xxx.jar` 启动)。该模式是 Spring Boot 应用最常见的部署方式。 已在 Spring Boot 2.x / 3.x / 4.x,JDK 8 / 11 / 17 / 21 上完成端到端验证。 ### 受影响 | 条件 | 说明 | |------|------| | fastjson 版本 | **1.2.68 – 1.2.83** | | 配置 | AutoType OFF + SafeMode OFF(**即默认配置**) | | 部署方式 | Spring Boot 可执行 fat-jar | | JDK | 8 / 11 / 17 / 21 均验证 | | Spring Boot | 2.x / 3.x / 4.x 均验证 | | 入口 | `JSON.parse`、`JSON.parseObject(String)`、`JSON.parseObject(String, Class)` 均可达 | > ⚠️ 指定目标 Class(如 `JSON.parseObject(body, SomeDto.class)`)**不是**缓解措施——攻击者可通过 DTO 中 Object / Map 类型的字段嵌套 payload。 ### 不受影响 | 条件 | 原因 | |------|------| | **fastjson ≥ 1.2.84** | 已修复:含 URL 特殊字符的类型名在任何资源探测或类加载之前即被拒绝 | | **fastjson2 所有版本** | 架构上已消除此漏洞根因 | | SafeMode = true | 在漏洞触发路径之前即拒绝所有 `@type` | | noneautotype 版本 | 漏洞相关代码在编译期被移除 | | 非 fat-jar 部署 | plain `java -jar`、uber-jar、Tomcat/Jetty WAR 部署不满足触发条件 | | fastjson ≤ 1.2.60 | 不存在漏洞相关代码路径 | ### fastjson2 不受影响 fastjson2 从架构上消除了此漏洞的根因: - **无资源探测**:类型解析路径中不存在基于用户可控类名的 `getResourceAsStream` 调用,类加载仅使用 `ClassLoader.loadClass()` 和 `Class.forName()` - **无注解信任绕过**:`@JSONType` 注解仅用于序列化配置,不作为类型解析的信任判据 - **白名单优先**:类型必须匹配白名单或经 `AutoTypeBeforeHandler` 显式批准,否则直接拒绝,无二次逃逸路径 - **autoType 默认关闭**:`SupportAutoType` 默认不启用,且已标记 `@Deprecated` 并附有安全警告 fastjson2 用户无需针对此漏洞采取任何行动。 ### 修复建议 #### fastjson 1.x 用户 | 优先级 | 措施 | 说明 | |--------|------|------| | **P0** | **升级至 fastjson 1.2.84** | 修复此漏洞:`com.alibaba:fastjson:1.2.84`([release notes](https://github.com/alibaba/fastjson/releases/tag/1.2.84)) | | **P0** | 或启用 SafeMode | `-Dfastjson.parser.safeMode=true`,或 `ParserConfig.getGlobalInstance().setSafeMode(true)`,或在 `fastjson.properties` 中设置 | | **P0** | 或切换 noneautotype 版本 | Maven 坐标示例:`com.alibaba:fastjson:1.2.83_noneautotype` | | **P1** | 迁移至 fastjson2 | 从架构上消除此漏洞,且默认配置即安全 | 1.2.84 的修复:在 `ParserConfig.checkAutoType` 和 `TypeUtils.loadClass` 中拒绝包含 URL 特殊字符(`:`/`!`)的类型名,使非类名字符串不会到达资源探测或类加载器;白名单 hash 命中后增加文本回验;accept 前缀不再覆盖 `ClassLoader`/`DataSource`/`RowSet` 危险基类;并修复了重复调用可能从缓存返回黑名单类的问题。 #### fastjson2 用户 无需针对此漏洞采取任何行动。一般性安全实践: - 避免显式启用 `JSONReader.Feature.SupportAutoType`(已废弃) - 如确需 autoType 能力,使用 `ContextAutoTypeBeforeHandler` 配置严格白名单 ### 致谢 感谢 FearsOff Cybersecurity 的 Kirill Firsov 发现并负责任地披露了该漏洞。 --- ## Note: fastjson2 and 2.0.63 / 附注:fastjson2 与 2.0.63 This advisory covers **CVE-2026-16723**, which is specific to the fastjson 1.x codebase: fastjson1's `checkAutoType` probes user-controlled type names with `getResourceAsStream`, and fastjson2 has no such probing path, so fastjson2 is not affected **by this CVE**. Independently, a separate AutoType hardening issue in fastjson2 (different root cause, publicly reported by Changting Tech) was fixed in **fastjson2 2.0.63** ([release notes](https://github.com/alibaba/fastjson2/releases/tag/2.0.63)). If you run fastjson2, upgrade to **2.0.63 or later**. 本公告针对的是 **CVE-2026-16723**,仅存在于 fastjson 1.x 代码库:fastjson1 的 `checkAutoType` 会对用户可控的类型名调用 `getResourceAsStream` 进行资源探测,fastjson2 不存在该路径,因此 fastjson2 不受**此 CVE** 影响。 另外,fastjson2 存在一个独立的 AutoType 加固问题(根因不同,由长亭科技公开报告),已在 **fastjson2 2.0.63** 中修复([release notes](https://github.com/alibaba/fastjson2/releases/tag/2.0.63))。使用 fastjson2 的用户请升级到 **2.0.63 及以上**。