Fastjson 1.2.83 reportedly exposed to gadget-free 0day RCE under default settings

Fastjson 1.2.83 reportedly exposed to gadget-free 0day RCE under default settings

N
News Editor
2026-07-23 08:41:36
Foresight reported that Fastjson 1.2.83 can still be exploited for remote code execution even when AutoType is set to false by default. The issue does not rely on a traditional gadget chain, which makes it notable from a defensive standpoint. According to the report, the vulnerability has been reproduced across multiple Java runtime versions, including JDK 8, 17, 21, and 25. It was also reproduced in an isolated environment using Spring Boot Loader. The report describes the issue as a 0day affecting Fastjson 1.2.83 under default configuration conditions.
Fastjsonsecurity vulnerabilityremote code execution0dayJDKSpring Boot Loader

Foresight reported that Fastjson 1.2.83 remains vulnerable to a 0day remote code execution issue even with AutoType=false under the default configuration.

According to the report, the exploit does not require a traditional gadget chain. The issue has been reproduced on JDK 8, 17, 21, and 25, as well as in an isolated environment using Spring Boot Loader.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.