Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crf3-v9rr-v7hj

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

EPSS

Процентиль: 34%
0.00413
Низкий

9 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9
nvd
8 дней назад

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

CVSS3: 9
fstec
10 дней назад

Уязвимость механизма AutoType библиотеки языка программирования Java Fastjson, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 34%
0.00413
Низкий

9 Critical

CVSS3

Дефекты

CWE-20