Watchers Lab

← Back to Community

Community discussions are public to read. To post, reply, or watch members, please sign in or create an account.

Alibaba's JSON librarya has a critical flaw in Fastjson w/ no patch

Posted by DiabloChops on 07/25/2026 at 06:28 PM

ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Comments

No comments yet.

Sign in or create an account to reply to this discussion.