Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

CVE-2026-16723 is a remote code execution vulnerability in Fastjson 1.2.68 through 1.2.83, the 1.x line of Alibaba’s Java JSON library. The maintainer’s advisory ties it to specific conditions: a Spring Boot executable fat JAR, SafeMode turned off, and a parsing path that accepts JSON an attacker can influence. The project names Fastjson 1.2.84 as the fix. The GitHub Advisory Database, however, lists no patched version for this CVE, so the 1.2.84 fix rests on the project’s own advisory and release page. Confirm the fixed artifact in your own dependency source before you treat the issue as closed.

Who is in scope

The maintainer advisory describes the trigger as a set of conditions that must hold together. Check them against the running service, because packaging and runtime configuration matter as much as the version number.

Condition What the advisory states How to check
Fastjson version Affected range is 1.2.68 through 1.2.83. Version 1.2.84 is the stated fix. Maven: mvn dependency:tree -Dincludes=com.alibaba:fastjson. Gradle: ./gradlew dependencies --configuration runtimeClasspath, then search the output for com.alibaba:fastjson.
AutoType Not a precondition. The advisory says the flaw is exploitable with AutoType left off. Disabling AutoType does not clear exposure on its own (see the AutoType section below).
SafeMode Affected only when SafeMode is off. The advisory says SafeMode enabled is not affected. Check the JVM flag -Dfastjson.parser.safeMode, any ParserConfig setter call in application code, and the fastjson.properties configuration. If none of the three enables it, SafeMode is off for that service.
Packaging Spring Boot executable fat JAR. The advisory says non-fat-JAR deployments do not meet the stated trigger condition. Run jar tf your-app.jar | grep BOOT-INF/lib/fastjson. A Spring Boot fat JAR keeps its dependencies under BOOT-INF/lib/, so a matching entry confirms both the packaging and the embedded Fastjson version.
Input reachability The advisory names JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class) as entry points. The trigger requires that an attacker can influence the JSON these calls receive. Trace request bodies, message-queue payloads, uploaded files, and cached data to any of those calls. Include code paths that run on a schedule or on startup.

Specifying a target class does not limit what arrives. Code such as JSON.parseObject(body, SomeDto.class) is not mitigation by itself, because the advisory warns that payloads can be nested inside Object or Map fields of that class.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The packaging condition is narrow. The advisory treats non-fat-JAR deployments as outside this trigger, but that is a statement about this CVE only. It does not show that other packaging formats are free of deserialization risk, so keep those services in the normal inventory.

Why disabling AutoType is not enough

A common question is whether an application on 1.2.83 is safe when AutoType is off. The maintainer advisory says the flaw is exploitable “under fastjson’s stock default configuration — no AutoType enablement required, no classpath gadget required.” Turning AutoType off therefore does not by itself remove the stated conditions. SafeMode state, packaging, and input reachability still determine whether a given service is exposed.

How the trust branch is reached

Fastjson 1.x resolves type names that appear in JSON. The maintainer advisory describes the vulnerable path as probing user-controlled type names for resources, with the @JSONType annotation acting as a trust signal. That annotation is normally used to configure how a class is serialized and parsed. The advisory’s point is that, in this path, it is treated as a trust signal, which is why the flaw is described as a trust branch.

The 1.2.84 changes reject type names that contain URL-special characters, such as : and !, before any resource probing or class loading happens. The advisory also describes additional validation around whitelist matches and cached classes. Rejecting these names at the start means a user-supplied name never reaches the probing step.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remediation options

The advisory lists four routes. Only the upgrade moves to a release the project labels as fixed. The other three are mitigations on the 1.x line or a change of library, so each one needs the same verification as an upgrade.

Option What the advisory says Trade-offs and checks
Upgrade to Fastjson 1.2.84 The project’s stated fix. The Fastjson repository release page shows 1.2.84 released July 29, 2026. Run full regression tests on every JSON path. Confirm the resolved version after the build, because a parent BOM or another library can pin an older Fastjson.
Enable SafeMode SafeMode enabled is not affected. Set it with -Dfastjson.parser.safeMode=true, the ParserConfig setter, or the fastjson.properties configuration. The advisory does not describe behavioural side effects, so test each endpoint that deserializes JSON. Confirm the setting is active in the running process, not only in a build file or a test profile.
Use the noneautotype build The advisory lists com.alibaba:fastjson:1.2.83_noneautotype as not affected by this path. This is still a 1.x build. Verify its provenance from your trusted artifact repository and treat it as an interim measure rather than a permanent fix.
Migrate to Fastjson2 The project says Fastjson2 is not affected by this CVE because the relevant resource-probing path is absent. The claim covers this CVE only. A code and dependency change, not a drop-in replacement. Scope it as a separate project with its own compatibility testing.

Triage and remediation order

  1. Inventory every Fastjson artifact. Run the Maven or Gradle command from the scope table on each service, including services that receive Fastjson transitively. F5 Labs (July 29, 2026) recommends software composition analysis or a manual inventory.
  2. Rank services by the scope table. Prioritize any service that is on an affected version, runs as a fat JAR, has SafeMode off, and passes attacker-influenced JSON to a named parsing call.
  3. If an upgrade cannot happen immediately, enable SafeMode in the running process and test it, or deploy the noneautotype build after provenance checks.
  4. Upgrade to 1.2.84 in staging and run regression tests. Then confirm the built artifact contains the fixed version with jar tf your-app.jar | grep BOOT-INF/lib/fastjson, which should list fastjson-1.2.84.jar.
  5. Keep network controls and monitoring in place. They reduce exposure, but they do not show the library is fixed; only the artifact check does that.
  6. Scope a Fastjson2 migration for the long term, separately from the emergency change.

If the version checks do not agree

  • The source shows 1.2.84, but the running service does not. The container image or deployed JAR was not rebuilt. Check the artifact inside the deployed image, not the project file.
  • The build resolves an older Fastjson. A parent BOM or another library pins it. The mvn dependency:tree output shows the winning version, and a dependencyManagement entry can override it.
  • SafeMode appears enabled. The setting exists only in a test profile or a startup script that production does not use. Check the exact start command of the production process.

Conflicting fixed-version data

The sources disagree on whether a patched release exists. The maintainer advisory says 1.2.84 fixes the issue, and the Fastjson repository release page shows 1.2.84 released July 29, 2026. The GitHub Advisory Database record, published July 23, 2026 and updated August 7, 2026, lists “Patched versions: None.” This article could not read the NVD entry for CVE-2026-16723, so NVD’s position is not reflected here.

Do not treat the database field as proof that no fix exists, and do not assume every database agrees that 1.2.84 is fixed. Check the coordinates your build actually resolves and the artifact from your trusted repository, then test. In internal reports, attribute each claim to its own source.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Severity, exploitation reporting, and credit

  • Severity. The GitHub Advisory Database rates the issue Critical with a CVSS v3 base score of 9.0. Its vector lists network attack vector, high attack complexity, no privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.
  • Prevalence. No published count of affected applications, deployments, or organizations was found. The severity score is not a measure of how many systems are exposed.
  • Exploitation. The Cloud Security Alliance AI Safety Initiative (July 27, 2026) and F5 Labs (July 29, 2026) describe active exploitation. Both are secondary reports from July 2026. This article has not verified whether that activity continues as of October 2026, so check current threat intelligence before describing it as ongoing.
  • Credit. The project advisory credits Kirill Firsov of FearsOff Cybersecurity with discovering and responsibly disclosing the vulnerability.

Vendor and third-party guidance

  • Tencent Cloud Security (July 23, 2026). Recommends SafeMode, strict JSON schema validation or allowlisting before deserialization where appropriate, or replacing Fastjson. The notice states that removing third-party gadget classes is not sufficient for the vulnerability it describes.
  • Huawei PSIRT (notice dated within July 22–28, 2026). States that an IPS signature database released after July 23, 2026 can detect and defend against network-layer attacks for specified Huawei firewall products. Coverage depends on product model and configuration, so confirm it for your own device.

The vendor guidance matches the project’s own options, with the addition of schema validation and allowlisting as input controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.