Skip to content

Add affected Maven package and version range to GHSA-crf3-v9rr-v7hj (CVE-2026-16723, com.alibaba:fastjson) - #9006

Merged
advisory-database[bot] merged 1 commit into
github:mainfrom
timtebeek:timtebeek-GHSA-crf3-v9rr-v7hj
Aug 7, 2026
Merged

Add affected Maven package and version range to GHSA-crf3-v9rr-v7hj (CVE-2026-16723, com.alibaba:fastjson)#9006
advisory-database[bot] merged 1 commit into
github:mainfrom
timtebeek:timtebeek-GHSA-crf3-v9rr-v7hj

Conversation

@timtebeek

Copy link
Copy Markdown
Contributor

This advisory is currently published with an empty affected array, so it carries no package or version information. That makes it invisible to tooling that resolves advisories to Maven coordinates, even though the affected package and the fixed version are both public.

This PR adds the affected package and range, based on the upstream advisory linked from the record:

  • Package: com.alibaba:fastjson (Maven)
  • Introduced: 1.2.68
  • Fixed: 1.2.84

Supporting references

  • The upstream advisory, Security Advisory: Remote Code Execution in fastjson 1.2.68–1.2.83 (already referenced in the record), scopes the vulnerability to fastjson 1.2.68 through 1.2.83 and states that fastjson ≤ 1.2.60 is not affected because the vulnerable code path does not exist. Its first remediation step is to upgrade to com.alibaba:fastjson:1.2.84; enabling SafeMode and switching to the 1.2.83_noneautotype build are listed as alternatives for users who cannot upgrade.
  • The details text already in this record likewise describes the range as "fastjson 1.2.68 through 1.2.83".
  • alibaba/fastjson release 1.2.84 was published 2026-07-29, after this advisory was imported on 2026-07-23, which is why the record predates the fix. The artifact is available on Maven Central at com/alibaba/fastjson/1.2.84.

I have also added a PACKAGE reference to the upstream repository and a WEB reference to the 1.2.84 release, to support the fixed event.

Note that the upstream advisory title still describes 1.2.83 as "the last 1.x release", which was accurate when it was written but no longer is.

Copilot AI balanced review requested due to automatic review settings August 6, 2026 15:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@advisory-database
advisory-database Bot merged commit 13b01af into github:main Aug 7, 2026
1 of 2 checks passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @timtebeek! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@timtebeek
timtebeek deleted the timtebeek-GHSA-crf3-v9rr-v7hj branch August 7, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants