Fastjson 1.2.68 through 1.2.83, bundled inside a Spring Boot executable fat-JAR, can be tricked into loading and running attacker-supplied code from a crafted JSON request. That’s true whenever ...
Fastjson 1.x flaw CVE-2026-16723 can trigger unauthenticated RCE in Spring Boot fat-JAR apps, with attacks reported and no ...