YYaaa News

Fastjson 1.x hit by gadget-free RCE | end-of-life library, only fix is migration to Fastjson2

TL;DR

Security researcher Kirill Firsov disclosed a gadget-free RCE in Fastjson 1.2.83 (the final 1.x release) — no classpath gadget needed, no autoTypeSupport toggle required, one payload straight to RCE across JDK 8, 17 and 21. Fastjson 1.x went out of maintenance in October 2024. Migrate to Fastjson2.

Security researcher Kirill Firsov disclosed a gadget-free remote code execution vulnerability in Fastjson 1.2.83 (the final release of the 1.x line) — no exploitable class on classpath required, no autoTypeSupport toggle needed, a single payload goes straight to RCE. Confirmed reproducible on JDK 8, 17 and 21.

The problem: Fastjson 1.x went out of maintenance in October 2024 and the maintainers are extremely unlikely to ship a security patch. Firsov points at the only remaining action: upgrade to Fastjson2, or enable SafeMode in startup arguments and config files. 1.x remains one of the most widely deployed Java JSON libraries in production; every previous CVE hinged on gadget-chain exploitation, and this gadget-free variant forces the entire historical risk assessment to be redone.

Audit dependencies now and move to Fastjson2. There is no alternative — leaving 1.x in place is holding the door open for a future public exploit.

via Kirill Firsov
Fastjson 1.x 曝無 gadget RCE|官方已停止維護,唯一出路是遷移到 Fastjson2