iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
CVE-2026-16723 is a remote code execution vulnerability in Fastjson 1.2.68 through 1.2.83, the 1.x line of Alibaba’s Java JSON library. The maintainer’s advisory ties it to specific conditions: a Spring Boot executable fat JAR, SafeMode turned off, and a parsing path that accepts JSON an attacker can influence. The project names Fastjson 1.2.84 as the fix. The GitHub Advisory Database, however, lists no patched version for this CVE, so the 1.2.84 fix rests on the project’s own advisory and release page. Confirm the fixed artifact in your own dependency source before you treat the issue as closed.
Who is in scope
The maintainer advisory describes the trigger as a set of conditions that must hold together. Check them against the running service, because packaging and runtime configuration matter as much as the version number.
| Condition | What the advisory states | How to check |
|---|---|---|
| Fastjson version | Affected range is 1.2.68 through 1.2.83. Version 1.2.84 is the stated fix. | Maven: mvn dependency:tree -Dincludes=com.alibaba:fastjson. Gradle: ./gradlew dependencies --configuration runtimeClasspath, then search the output for com.alibaba:fastjson. |
| AutoType | Not a precondition. The advisory says the flaw is exploitable with AutoType left off. | Disabling AutoType does not clear exposure on its own (see the AutoType section below). |
| SafeMode | Affected only when SafeMode is off. The advisory says SafeMode enabled is not affected. | Check the JVM flag -Dfastjson.parser.safeMode, any ParserConfig setter call in application code, and the fastjson.properties configuration. If none of the three enables it, SafeMode is off for that service. |
| Packaging | Spring Boot executable fat JAR. The advisory says non-fat-JAR deployments do not meet the stated trigger condition. | Run jar tf your-app.jar | grep BOOT-INF/lib/fastjson. A Spring Boot fat JAR keeps its dependencies under BOOT-INF/lib/, so a matching entry confirms both the packaging and the embedded Fastjson version. |
| Input reachability | The advisory names JSON.parse, JSON.parseObject(String), and JSON.parseObject(String, Class) as entry points. The trigger requires that an attacker can influence the JSON these calls receive. |
Trace request bodies, message-queue payloads, uploaded files, and cached data to any of those calls. Include code paths that run on a schedule or on startup. |
Specifying a target class does not limit what arrives. Code such as JSON.parseObject(body, SomeDto.class) is not mitigation by itself, because the advisory warns that payloads can be nested inside Object or Map fields of that class.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The packaging condition is narrow. The advisory treats non-fat-JAR deployments as outside this trigger, but that is a statement about this CVE only. It does not show that other packaging formats are free of deserialization risk, so keep those services in the normal inventory.
#1 Best Overall
Why disabling AutoType is not enough
A common question is whether an application on 1.2.83 is safe when AutoType is off. The maintainer advisory says the flaw is exploitable “under fastjson’s stock default configuration — no AutoType enablement required, no classpath gadget required.” Turning AutoType off therefore does not by itself remove the stated conditions. SafeMode state, packaging, and input reachability still determine whether a given service is exposed.
How the trust branch is reached
Fastjson 1.x resolves type names that appear in JSON. The maintainer advisory describes the vulnerable path as probing user-controlled type names for resources, with the @JSONType annotation acting as a trust signal. That annotation is normally used to configure how a class is serialized and parsed. The advisory’s point is that, in this path, it is treated as a trust signal, which is why the flaw is described as a trust branch.
The 1.2.84 changes reject type names that contain URL-special characters, such as : and !, before any resource probing or class loading happens. The advisory also describes additional validation around whitelist matches and cached classes. Rejecting these names at the start means a user-supplied name never reaches the probing step.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsRemediation options
The advisory lists four routes. Only the upgrade moves to a release the project labels as fixed. The other three are mitigations on the 1.x line or a change of library, so each one needs the same verification as an upgrade.
Rank #3
| Option | What the advisory says | Trade-offs and checks |
|---|---|---|
| Upgrade to Fastjson 1.2.84 | The project’s stated fix. The Fastjson repository release page shows 1.2.84 released July 29, 2026. | Run full regression tests on every JSON path. Confirm the resolved version after the build, because a parent BOM or another library can pin an older Fastjson. |
| Enable SafeMode | SafeMode enabled is not affected. Set it with -Dfastjson.parser.safeMode=true, the ParserConfig setter, or the fastjson.properties configuration. |
The advisory does not describe behavioural side effects, so test each endpoint that deserializes JSON. Confirm the setting is active in the running process, not only in a build file or a test profile. |
| Use the noneautotype build | The advisory lists com.alibaba:fastjson:1.2.83_noneautotype as not affected by this path. |
This is still a 1.x build. Verify its provenance from your trusted artifact repository and treat it as an interim measure rather than a permanent fix. |
| Migrate to Fastjson2 | The project says Fastjson2 is not affected by this CVE because the relevant resource-probing path is absent. The claim covers this CVE only. | A code and dependency change, not a drop-in replacement. Scope it as a separate project with its own compatibility testing. |
Triage and remediation order
- Inventory every Fastjson artifact. Run the Maven or Gradle command from the scope table on each service, including services that receive Fastjson transitively. F5 Labs (July 29, 2026) recommends software composition analysis or a manual inventory.
- Rank services by the scope table. Prioritize any service that is on an affected version, runs as a fat JAR, has SafeMode off, and passes attacker-influenced JSON to a named parsing call.
- If an upgrade cannot happen immediately, enable SafeMode in the running process and test it, or deploy the noneautotype build after provenance checks.
- Upgrade to 1.2.84 in staging and run regression tests. Then confirm the built artifact contains the fixed version with
jar tf your-app.jar | grep BOOT-INF/lib/fastjson, which should listfastjson-1.2.84.jar. - Keep network controls and monitoring in place. They reduce exposure, but they do not show the library is fixed; only the artifact check does that.
- Scope a Fastjson2 migration for the long term, separately from the emergency change.
If the version checks do not agree
- The source shows 1.2.84, but the running service does not. The container image or deployed JAR was not rebuilt. Check the artifact inside the deployed image, not the project file.
- The build resolves an older Fastjson. A parent BOM or another library pins it. The
mvn dependency:treeoutput shows the winning version, and adependencyManagemententry can override it. - SafeMode appears enabled. The setting exists only in a test profile or a startup script that production does not use. Check the exact start command of the production process.
Conflicting fixed-version data
The sources disagree on whether a patched release exists. The maintainer advisory says 1.2.84 fixes the issue, and the Fastjson repository release page shows 1.2.84 released July 29, 2026. The GitHub Advisory Database record, published July 23, 2026 and updated August 7, 2026, lists “Patched versions: None.” This article could not read the NVD entry for CVE-2026-16723, so NVD’s position is not reflected here.
Do not treat the database field as proof that no fix exists, and do not assume every database agrees that 1.2.84 is fixed. Check the coordinates your build actually resolves and the artifact from your trusted repository, then test. In internal reports, attribute each claim to its own source.
Rank #4
Severity, exploitation reporting, and credit
- Severity. The GitHub Advisory Database rates the issue Critical with a CVSS v3 base score of 9.0. Its vector lists network attack vector, high attack complexity, no privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.
- Prevalence. No published count of affected applications, deployments, or organizations was found. The severity score is not a measure of how many systems are exposed.
- Exploitation. The Cloud Security Alliance AI Safety Initiative (July 27, 2026) and F5 Labs (July 29, 2026) describe active exploitation. Both are secondary reports from July 2026. This article has not verified whether that activity continues as of October 2026, so check current threat intelligence before describing it as ongoing.
- Credit. The project advisory credits Kirill Firsov of FearsOff Cybersecurity with discovering and responsibly disclosing the vulnerability.
Vendor and third-party guidance
- Tencent Cloud Security (July 23, 2026). Recommends SafeMode, strict JSON schema validation or allowlisting before deserialization where appropriate, or replacing Fastjson. The notice states that removing third-party gadget classes is not sufficient for the vulnerability it describes.
- Huawei PSIRT (notice dated within July 22–28, 2026). States that an IPS signature database released after July 23, 2026 can detect and defend against network-layer attacks for specified Huawei firewall products. Coverage depends on product model and configuration, so confirm it for your own device.
The vendor guidance matches the project’s own options, with the addition of schema validation and allowlisting as input controls.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

