Maven package intelligence
com.alibaba:fastjson Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Maven package com.alibaba:fastjson, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 2
- Known exploited vulnerabilities affecting com.alibaba:fastjson
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- com.alibaba:fastjson KEV with sensor-observed exploitation activity
Review com.alibaba:fastjson exploitation against the versions you run
Two of the two exploited com.alibaba:fastjson vulnerabilities tracked here are not in CISA KEV.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
Attested com.alibaba:fastjson vulnerabilities
2 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2026-16723
Remote Code Execution in fastjson 1.2.68–1.2.83 |
Beyond CISA | 25 Jul 2026 |
|
CVE-2017-18349
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary... |
Beyond CISA | 23 Oct 2018 |
Recurring weakness patterns
Improper Input Validation and Deserialization of Untrusted Data account for mapped occurrences across this com.alibaba:fastjson KEV portfolio.