CVE-2026-16723: Pre-Auth RCE in Fastjson 1.x via the @JSONType Trust Branch
A vulnerability with a CVSS score of 9.0 was found in Fastjson 1.2.68–1.2.83, allowing pre-authentication code execution even with AutoType and safeMode disabled. No patch is available: Alibaba has declared the 1.x branch obsolete and advises migrating to Fastjson2.
- All Fastjson 1.2.68–1.2.83 releases vulnerable, no patch will be issued
- Attack works with AutoType and safeMode disabled
- Class loaded via jar:http:// URL through class loader
- Alibaba recommends migration to Fastjson2
Read next
Security