Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-25845

39
FAUCET Score

CVE-2022-25845 is a critical deserialization vulnerability affecting Alibaba Fastjson versions prior to 1.2.83, as well as Alibaba and Oracle Communications Cloud Native Core Unified Data Repository. This flaw allows attackers to bypass autoType shutdown restrictions under specific conditions, leading to remote server compromise. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, the vulnerability has a high EPSS score and has garnered community attention, including a detailed analysis, though no public exploit code or Metasploit modules are available.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.2.83CPE matchmatch criteria
cpe:2.3:a:alibaba:fastjson:*:*:*:*:*:*:*:*
22.2.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
17.77%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1777 is in the 93rd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.alibaba:fastjsonFixed in: 1.2.83
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11Fixed in: fastjson
View patch
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: fastjson
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: fastjson

Vendor Advisories (2)

mavenGHSA-pv7h-hx5h-mgfjhigh

Unsafe deserialization in com.alibaba:fastjson

Jun 11, 2022
redhatCVE-2022-25845Important

fastjson: autoType shutdown restriction bypass leads to deserialization

Jun 10, 2022

References

github.com / alibaba/fastjson/commit/35db4adad70c32089542f23c272def1ad920a60d
PatchThird Party Advisory
github.com / alibaba/fastjson/commit/8f3410f81cbd437f7c459f8868445d50ad301f15
PatchThird Party Advisory
github.com / alibaba/fastjson/releases/tag/1.2.83
Release NotesThird Party Advisory
github.com / alibaba/fastjson/wiki/security_update_20220523
Third Party Advisory
snyk.io / vuln/SNYK-JAVA-COMALIBABA-2859222
Third Party Advisory
ddosi.org / fastjson-poc
ExploitThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory