CVE-2023-42276: Hutool

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.

Affected products

  • Hutool Hutool: before 5.8.22 (fixed in 5.8.22)

Published 2023-09-08. Last modified 2026-06-17.