Get real-time updates on Telegram
P2Verified
FASTJSON Includes Functionality from Untrusted Control Sphere
CVE-2025-70974 affects com.alibaba:fastjson. CVSS base score 10.0 (GitHub Advisory Database). EPSS 0.00767 (percentile 0.53961), scored 2026-10-04. Affected range: < 1.2.48. Fixed version: 1.2.48.
- CVE
- CVE-2025-70974
- Product
- com.alibaba:fastjson
- CCR priority
- 75.0 /100 (P2)
- CVSS
- 10.0 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · GitHub Advisory Database
- EPSS
- 0.00767 · percentile 0.53961 · 2026-10-04
- KEV
- no
- Exploit signals
- Source reports exploitation.
- Signal evidence
- Source advisory: source reports exploitation (exploited in the wild).
Affected products
- com.alibaba:fastjson · < 1.2.48 · Fixed version: 1.2.48
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-70974.html