A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
PoC: fastjson-jsontype-rce-lab
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
This is N-day patch we releasing by testing our model capabilities
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
Fastjson RCE
[POC] CVE-2026-16723 — CVE-2026-16723
CVE-2026-16723 - Draft
PoC: CVE-2026-16723
fastjson jsontype利用
PoC: fastjson-check
Find fastjson in your JARs and Spring Boot fat-JARs, and check exposure to CVE-2026-16723. Zero dependencies, fully offline. 一条命令排查 fastjson 漏洞影响范围。
PoC: fastjson-rce-lab
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free