CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Configurations

No configuration.

History

23 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 09:16

Updated : 2026-07-23 15:01


NVD link : CVE-2026-16723

Mitre link : CVE-2026-16723

CVE.ORG link : CVE-2026-16723


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data