FastSpring A.I CyberSecurity Scoring
FastSpring
Company Information
Website:http://fastspring.com
Employees number:188
Number of followers:13,641
NAICS:5112
Industry Type:Software Development
Homepage:fastspring.com
FastSpring Risk Score (AI oriented)
Between 750 and 799
FastSpringSoftware Development
Updated:
25/07/2026
25/07/2026
750/1000
Fair
Baa
FastSpring Global Score (TPRM)
xxxx
FastSpringSoftware Development
Score locked

FastSpringFair
Current Score
750Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750
JULY 2026
753
Vulnerability
21 Jul 2026 • FastSpring
Alibaba and Spring Boot: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Critical Fastjson Vulnerability (CVE-2026-16723) Under Active Exploitation
750
CRITICAL-3
ALIFAS1784996806
Critical Fastjson Vulnerability (CVE-2026-16723) Under Active Exploitation
Security researchers from ThreatBook and Imperva have identified active exploitation of a critical vulnerability in Fastjson, Alibaba’s widely used JSON library for Java. Tracked as CVE-2026-16723 (CVSS 9.0), the flaw allows unauthenticated remote code execution (RCE) in Spring Boot applications when processing malicious JSON requests, executing code with the privileges of the Java process.
### Key Details
- Affected Versions: Fastjson 1.2.68 through 1.2.83, when used in Spring Boot executable fat-JARs with SafeMode disabled (its default state).
- Exploitation Requirements: Attackers must send a crafted JSON payload to a network-reachable endpoint using vulnerable parsing methods (`JSON.parse`, `JSON.parseObject`). No AutoType enablement or classpath gadgets are required.
- Attack Vector: The flaw stems from Fastjson’s type-resolution mechanism, where an attacker-controlled `@type` value can trigger a class-resource lookup. In Spring Boot fat-JARs, this can fetch malicious bytecode via nested JAR paths or remote JAR downloads (including through `/proc/self/fd` on newer JDKs).
- Unaffected Deployments: Plain non-fat JARs, generic uber-JARs, and Tomcat/Jetty WAR deployments are not vulnerable.
### Disclosure & Mitigation
- Disclosure: The vulnerability was responsibly reported by Kirill Firsov of FearsOff Cybersecurity and publicly disclosed by Alibaba on July 21.
- No Patch Available: As of July 25, Alibaba has not released a fixed Fastjson 1.x version. The recommended long-term solution is migrating to Fastjson2, which is unaffected.
- Workarounds:
- Enable SafeMode (`-Dfastjson.parser.safeMode=true`).
- Use the restricted build `com.alibaba:fastjson:1.2.83_noneautotype`.
### Exploitation in the Wild
- ThreatBook detected in-the-wild attacks July 22, two days after adding detection rules. Their testing confirmed full RCE on JDK 8 in Spring Boot fat-JARs, though embedded Tomcat deployments only resulted in remote JAR fetches or SSRF.
- Imperva observed exploitation attempts targeting financial services, healthcare, computing, and retail sectors, primarily in the U.S., with smaller volumes in Singapore and Canada. Attackers used browser impersonators (70%), along with Ruby and Go tools (30%).
- No Confirmed Breaches: Neither vendor provided evidence of successful exploitation against real-world targets, and CISA’s Known Exploited Vulnerabilities (KEV) catalog does not currently list the flaw.
### Technical Context
- The vulnerability bypasses previous mitigations, including Alibaba’s 2022 AutoType bypass patch (Fastjson 1.2.83), which now falls within the affected range.
- Fastjson2 is unaffected due to architectural changes in its resource-probing and annotation-based trust mechanisms.
Organizations are advised to audit direct and transitive Fastjson dependencies, monitor for suspicious `@type` values, unexpected outbound connections, and unauthorized child processes. No patched Fastjson 1.x release is available as of this report.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2026
753
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for FastSpring ??
What was FastSpring's A.I Rankiteo Cyber Score in July 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in June 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in May 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in April 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in March 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in February 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in January 2026 ??
What was FastSpring's A.I Rankiteo Cyber Score in December 2025 ??
What was FastSpring's A.I Rankiteo Cyber Score in November 2025 ??
What was FastSpring's A.I Rankiteo Cyber Score in October 2025 ??
What was FastSpring's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on FastSpring's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with FastSpring ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view FastSpring's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?