Dossier
Spring Boot
Coverage of Spring Boot in the Nexus archive.
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva report attackers exploiting a critical Fastjson 1.x vulnerability (CVE-2026-16723) in Spring Boot applications, enabling unauthenticated code execution with Java process privileges. Alibaba's CVSS score of 9.0 highlights the severity, but no patch is currently available.