CRITICALAdvisoryJul 27, 2026
Action required
Immediately inventory all applications using Fastjson 1.x. Enable SafeMode in affected instances or migrate to Fastjson2. Hunt for POST requests with suspicious serialized payloads targeting endpoints known to deserialize user input.
Affected products
Fastjson 1.xAlibabaSpring Boot
CVE IDs