Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
FastSpring

FastSpring Vendor Cyber Rating & Cyber Score

fastspring.com

FastSpring is how SaaS, software, and digital product companies sell online in more places around the world. We handle all payment needs from checkout to taxes so you can go farther faster. Founded in 2005, we are a privately owned company headquartered in Santa Barbara with offices in Amsterdam, Belfast and Halifax. For more information, please visit https://www.fastspring.com.


FastSpring A.I CyberSecurity Scoring

FastSpring
Company Information
Website:http://fastspring.com
Employees number:188
Number of followers:13,641
NAICS:5112
Industry Type:Software Development
Homepage:fastspring.com
FastSpring Risk Score (AI oriented)
Between 750 and 799
logo
FastSpringSoftware Development
Updated:
25/07/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
FastSpring Global Score (TPRM)
xxxx
logo
FastSpringSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FastSpring
FastSpringFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750Before Incident
JULY 2026
753Before Incident
Vulnerability
21 Jul 2026FastSpring
Alibaba and Spring Boot: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Critical Fastjson Vulnerability (CVE-2026-16723) Under Active Exploitation

750After Incident
CRITICAL-3
ALIFAS1784996806
Critical Fastjson Vulnerability (CVE-2026-16723) Under Active Exploitation Security researchers from ThreatBook and Imperva have identified active exploitation of a critical vulnerability in Fastjson, Alibaba’s widely used JSON library for Java. Tracked as CVE-2026-16723 (CVSS 9.0), the flaw allows unauthenticated remote code execution (RCE) in Spring Boot applications when processing malicious JSON requests, executing code with the privileges of the Java process. ### Key Details - Affected Versions: Fastjson 1.2.68 through 1.2.83, when used in Spring Boot executable fat-JARs with SafeMode disabled (its default state). - Exploitation Requirements: Attackers must send a crafted JSON payload to a network-reachable endpoint using vulnerable parsing methods (`JSON.parse`, `JSON.parseObject`). No AutoType enablement or classpath gadgets are required. - Attack Vector: The flaw stems from Fastjson’s type-resolution mechanism, where an attacker-controlled `@type` value can trigger a class-resource lookup. In Spring Boot fat-JARs, this can fetch malicious bytecode via nested JAR paths or remote JAR downloads (including through `/proc/self/fd` on newer JDKs). - Unaffected Deployments: Plain non-fat JARs, generic uber-JARs, and Tomcat/Jetty WAR deployments are not vulnerable. ### Disclosure & Mitigation - Disclosure: The vulnerability was responsibly reported by Kirill Firsov of FearsOff Cybersecurity and publicly disclosed by Alibaba on July 21. - No Patch Available: As of July 25, Alibaba has not released a fixed Fastjson 1.x version. The recommended long-term solution is migrating to Fastjson2, which is unaffected. - Workarounds: - Enable SafeMode (`-Dfastjson.parser.safeMode=true`). - Use the restricted build `com.alibaba:fastjson:1.2.83_noneautotype`. ### Exploitation in the Wild - ThreatBook detected in-the-wild attacks July 22, two days after adding detection rules. Their testing confirmed full RCE on JDK 8 in Spring Boot fat-JARs, though embedded Tomcat deployments only resulted in remote JAR fetches or SSRF. - Imperva observed exploitation attempts targeting financial services, healthcare, computing, and retail sectors, primarily in the U.S., with smaller volumes in Singapore and Canada. Attackers used browser impersonators (70%), along with Ruby and Go tools (30%). - No Confirmed Breaches: Neither vendor provided evidence of successful exploitation against real-world targets, and CISA’s Known Exploited Vulnerabilities (KEV) catalog does not currently list the flaw. ### Technical Context - The vulnerability bypasses previous mitigations, including Alibaba’s 2022 AutoType bypass patch (Fastjson 1.2.83), which now falls within the affected range. - Fastjson2 is unaffected due to architectural changes in its resource-probing and annotation-based trust mechanisms. Organizations are advised to audit direct and transitive Fastjson dependencies, monitor for suspicious `@type` values, unexpected outbound connections, and unauthorized child processes. No patched Fastjson 1.x release is available as of this report.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: Spring Boot applications using Fastjson 1.2.68 through 1.2.83 with SafeMode disabled
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for FastSpring ?
?
What was FastSpring's A.I Rankiteo Cyber Score in July 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in June 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in May 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in April 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in March 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in February 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in January 2026 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in December 2025 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in November 2025 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in October 2025 ?
?
What was FastSpring's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on FastSpring's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with FastSpring ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view FastSpring's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?