Maven package intelligence

com.alibaba:fastjson Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package com.alibaba:fastjson, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting com.alibaba:fastjson
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
2
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
com.alibaba:fastjson KEV with sensor-observed exploitation activity

Review com.alibaba:fastjson exploitation against the versions you run

Two of the two exploited com.alibaba:fastjson vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested com.alibaba:fastjson vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2026-16723

Remote Code Execution in fastjson 1.2.68–1.2.83

Beyond CISA 25 Jul 2026
CVE-2017-18349

parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary...

Beyond CISA 23 Oct 2018

Recurring weakness patterns

Improper Input Validation and Deserialization of Untrusted Data account for mapped occurrences across this com.alibaba:fastjson KEV portfolio.

Browse all KEVs →