CVE-2023-51080: Hutool

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.

Affected products

  • Hutool Hutool: from 5.8.22, before 5.8.25 (fixed in 5.8.25)

Published 2023-12-27. Last modified 2026-06-17.