Feed/CVE-2026-16723
CVE-2026-16723CRITICALCVSS 9.0

CVE-2026-16723

Published Jul 23, 2026·Updated Aug 7, 2026

NVD Description

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Affected Packages (1)

com.alibaba:fastjsonMAVEN
From 1.2.68
Fixed in = 1.2.83

Public Exploits & PoCs8 found

PoC: fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.

176

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.

2

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

This is N-day patch we releasing by testing our model capabilities

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

Fastjson RCE

1

[POC] CVE-2026-16723 — CVE-2026-16723

CVE-2026-16723 - Draft

PoC: CVE-2026-16723

fastjson jsontype利用

PoC: fastjson-check

Find fastjson in your JARs and Spring Boot fat-JARs, and check exposure to CVE-2026-16723. Zero dependencies, fully offline. 一条命令排查 fastjson 漏洞影响范围。

PoC: fastjson-rce-lab

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free