CVE-2025-70974Critical· 10.0▾ MidnightFastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.8%
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49449Low· 2.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-93993High· 8.8Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation
CVE-2026-73073High· 7.3Vim is an open source, command line text editor
CVE-2026-73851NoneKiota is an OpenAPI based HTTP Client code generator
CVE-2026-81305Medium· 6.8CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity
CVE-2026-54916High· 8.8NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox