Software
Service
Insights
Case & Story
Dev Platform
Sign In
Public Notices
Fastjson2 Remote Code Execution Vulnerability
Aug. 4, 2026 GMT+8:00
1.Overview

Recently, a remote code execution vulnerability has been disclosed in Fastjson2. Under the default configuration where SupportAutoType is disabled, the AutoType allowlist validation relies solely on hash matching rather than verifying the actual class name. This flaw allows attackers to bypass security controls and trigger arbitrary remote class loading.

Fastjson2 is a high-performance, next-generation JSON library for Java, developed by Alibaba. It provides efficient serialization and deserialization between Java objects and JSON strings. If you are a Fastjson2 user, check your system and implement timely security hardening.

Reference:

https://github.com/alibaba/fastjson2/issues/7702

2.Severity

important

(Severity: low, medium, important, and critical)

3.Affected Products

Affected versions:

Fastjson 2.x <= 2.0.62

Security versions:

Fastjson 2.x >= 2.0.63

4.Vulnerability Handling

This vulnerability has been fixed in later official versions. If your service version falls into the affected range, upgrade it to a latest secure version.

https://github.com/alibaba/fastjson2/releases/

Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.

5.Technical Support

Get more professional support at any time

Contact Us

Email: GlobalTechnicalService@iwhalecloud.com
Contact Us