CVE-2025-70974

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class,...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 09, 2026
Published Date
January 09, 2026
Last Updated
January 09, 2026
Vendor
Alibaba
Product
Fastjson
Description
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.

CVSS Scores

CVSS v3.1

10.0 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
poc
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:48:34 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:48:34 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel