Feed/CVE-2026-9497
CVE-2026-9497LOWCVSS 6.3

TCC-TRANSACTION has an Improper Input Validation vulnerability

Published May 26, 2026·Updated Jun 30, 2026

NVD Description

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Packages (1)

org.mengyun:tcc-transactionMAVEN
Fixed in = 2.1.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free