CVE-2022-25845
CRITICAL 9.8EPSS 18.7%
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 18.74% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2022-06-10
- Updated
- 2024-09-16
Proof-of-concept exploits (5)
- https://www.ddosi.org/fastjson-poc/
- cuijiung/fastjson-CVE-2022-258450★ · 2025-07-18
- luelueking/CVE-2022-25845-In-Spring109★ · 2024-11-07
- nerowander/CVE-2022-25845-exploit1★ · 2023-03-01
- ph0ebus/CVE-2022-25845-In-Spring7★ · 2024-12-01