CVE-2022-25845: Alibaba Fastjson
Critical severity, CVSS 9.8. EPSS: 18.7% chance of exploitation in the next 30 days.
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).
Affected products
- Alibaba Fastjson: before 1.2.83 (fixed in 1.2.83)
- Oracle Communications Cloud Native Core Unified Data Repository: version 22.2.0 only
Published 2022-06-10. Last modified 2026-06-17.