Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
fastjson-jsontype-rce-lab — Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls. | Kitploit
Tools/GitHubGitHub/dinosn/fastjson-jsontype-rce-lab
Static AnalysisDynamic Analysis (Sandboxing)Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHub
dinosn/fastjson-jsontype-rce-lab

fastjson-jsontype-rce-lab

View Repository
20392122 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.

Share

Fastjson @JSONType remote-JAR/FD-chain lab and detection

This repository now preserves two distinct Fastjson research tracks:

  • modern-fd/ is the recommended, marker-only reconstruction of the Fastjson 1.2.83 single-body remote-JAR/file-descriptor chain on Spring Boot 3, normal embedded Tomcat and JDK 17. It uses the literal fixed-DTO sink JSON.parseObject(body, BoundEnvelope.class) with AutoType disabled.
  • The original top-level Docker Compose lab preserves the earlier JDK 8 direct remote-class route. It is command-capable and should be treated as a legacy, isolated proof rather than the modern-JDK method.
  • scanner/ contains passive request/log detection, static artifact inventory and a non-executing reachability probe.

The bug: ParserConfig.checkAutoType probes every @type value for the @JSONType annotation by doing getResourceAsStream(typeName.replace('.','/') + ".class"). On modern Linux/JDK combinations, a remote jar:http probe can leave the JAR cached behind an open descriptor; later jar:file:/proc/self/fd/N probes in the same body can reopen it under valid class names and initialize an annotated class. The exact 1.2.83 composition works with AutoType disabled and through a fixed DTO containing List<Object>. Binding alone is therefore not a mitigation. Full walk-through: docs/MECHANISM.md.

Security review findings

The companion whole-project review covered 2,041 callable/static-initializer rows across all 193 Fastjson 1.2.83 production Java files. The table below prioritizes the highest-impact results; it is not a claim that every Fastjson deployment is affected. This repository directly reproduces F105. The remaining entries summarize separately sealed source review and bounded lab evidence.

PriorityFindingProven resultImportant boundary
1F105 — remote @JSONType bytecode executionAttacker-supplied class initialization through compatible Spring Boot loaders, including the JDK 8 direct route and the Linux/JDK 17 retained-JAR /proc/self/fd/N continuationRequires a parser-reachable @type carrier, compatible Boot/TCCL loader, egress, SafeMode/IgnoreAutoType off, and an exact attacker JAR. The modern fixed-DTO route additionally needs a generic value lane (the lab uses List<Object>), Linux procfs, a retained descriptor and exact name alignment; not universal across every JDK, loader, or OS
2F1/F45 — TemplatesImpl command executionMarker command execution through the fixed-DTO API, including an ignored body propertyRequires weakened server policy: class admission, AutoType, and private-field population or equivalent paths; pristine defaults block it
3F70/C016 — unbounded buffering and GZIP expansionTyped byte/InputStream and annotated DTO paths expand or buffer without an output cap; constrained-heap Java OOME was reproducedEndpoint/schema and attacker-byte reachability are required; production-wide outage was not established
4F18/C089 — parser-thread stack exhaustionDeeply nested ordinary object values can produce StackOverflowError under default parsingRequest-thread availability impact; not an invariant JVM or service-wide crash
5F120/C162 — fixed-schema HTTP SSRF/local-resource loadingBody-controlled JEditorPane/JTextPane.page performs HTTP requests and can load bounded file: content into Document stateRequires the application to declare the Swing type; no automatic response exfiltration or RCE was proven
6F118/C160 — hash-collision authorization/data-integrity failureA distinct Unicode FNV-1a-64 collision can bind to a privileged enum constant or route JSONPath mutation to the wrong bean setterRequires a usable collision and downstream trust or an exposed JSONPath mutation operation; no class admission or RCE
7F121/C163 — fixed JdbcRowSet JNDI reachabilityExact setter order caused one body-selected outbound JNDI/LDAP connectionEvidence stops at a connection: no naming response, object factory, bytecode loading, or RCE
8F2/F45 — default DNS resolutionAttacker-controlled hostname resolution works under default configuration and through an ignored fixed-DTO propertyDNS/OOB interaction only, not generic HTTP SSRF or RCE

See findings/FINDINGS.md for validation labels, prerequisites, lower-tier findings, remediation priorities, and explicit negative boundaries.

⚠️ Authorized use only

This repository is for education, defensive research, and authorized testing of systems you own or are explicitly permitted to test. Host publication, when supported for the modern lab's internal network, is requested on 127.0.0.1 only; its scripts drive the test entirely inside that isolated network. The modern lab has no process-execution primitive and sets only a fixed in-JVM marker. The legacy JDK 8 lab does execute id and writes its output to /tmp/PWNED; keep it isolated. Do not point the legacy exploit or active probe at unauthorized systems.

Scan your own environment

The scanner/ directory ships four dependency-free Python 3 tools (no pip installs).

  • fjdetect.py — passively inspect decoded JSON request bodies or structured JSON logs for remote-JAR seeds and /proc/self/fd or /dev/fd sequences.
  • fjscan_static.py — inventory jars/wars/ears for the vulnerable combination (content-backed, metadata-verified 1.2.83 × actual Spring Boot loader class content). Probe-bearing 1.2.48–1.2.82 releases and metadata/filename-only candidates are reported separately for review. CI-gate friendly (exit 2 on EXPOSED).
  • fjscan_probe.py — active, safe reachability check: fires the @type at a canary you control (built-in listener or Burp Collaborator / interactsh) and correlates the resource-fetch callback. Its built-in listener returns an empty 404; configure external listeners equivalently. A callback does not prove class loading or RCE.
  • fjpayload.py — generate remote-resource fetch bodies for manual testing; use only an empty/404 listener when execution is not intended.
# 1) passive request/log inspection
python3 scanner/fjdetect.py --ndjson gateway.jsonl

# 2) inventory build artifacts / unpacked images (parallel)
python3 scanner/fjscan_static.py /path/to/artifacts --threads 16

# 3) active probe across many domains — simplest: --auto fires baseline + plain + escaped comparison
#    DNS probes per target and prints a rollup; DNS callbacks land in your Burp Collaborator
python3 scanner/fjscan_probe.py --collaborator <sub>.oastify.com --auto --targets domains.txt --threads 50
cat domains.txt | python3 scanner/fjscan_probe.py --collaborator <sub>.oastify.com --auto --targets -

# 4) bulk fetch payloads for manual testing (one per domain, stable correlation token)
python3 scanner/fjpayload.py <collab-or-ip> --targets-file domains.txt

domains.txt = one target per line — a full [METHOD ]URL or a bare domain (expanded with --scheme / --target-port / --path); # comments allowed:

api.internal.example
POST https://svc.example/v1/ingest
10.0.0.7:8080

Options

fjscan_probe.py (active probe)

Download Tool