Alibaba's vulnerability profile centers on a focused set of widely deployed open-source and enterprise middleware products—particularly Nacos, Fastjson, Druid, and Alipay ActiveX Control—that serve critical roles in distributed systems, data access layers, and financial applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the recurring weakness classes, including deserialization of untrusted data, authentication bypass, path traversal, and improper input validation, reflect the complexity of large-scale integration platforms and the high-value targets they represent. Defenders should prioritize updates for these infrastructure and middleware components, particularly in internet-connected deployments; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alibaba, Inc. over time
Of all the CVEs published by Alibaba, Inc. as a CNA, 50.0% affect products that Alibaba, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Alibaba, Inc., 15.4% are self-published by Alibaba, Inc. as a CNA.
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29441CRITICAL Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.c | Apr 27, 2021 | 9.8 | 81 | NO | YES |
CVE-2021-29442HIGH Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform ma | Apr 27, 2021 | 7.5 | 69 | NO | YES |
CVE-2017-18349CRITICAL parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, a | Oct 23, 2018 | 9.8 | 64 | NO | YES |
CVE-2021-43116HIGH An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package | Jul 5, 2022 | 8.8 | 42 | NO | YES |
CVE-2026-16723CRITICAL A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType e | Jul 23, 2026 | 9.0 | 39 | NO | NO |
CVE-2022-25845CRITICAL The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under | Jun 10, 2022 | 9.8 | 39 | NO | NO |
CVE-2025-70974CRITICAL Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain pu | Jan 9, 2026 | 10.0 | 37 | NO | NO |
CVE-2007-0827MEDIUM The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid i | Feb 7, 2007 | 6.8 | 28 | NO | YES |
CVE-2021-33800HIGH In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal. | Nov 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-44667MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters. | Mar 11, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alibaba, Inc..
Media articles that mention a CVE ID that affects a product developed by Alibaba, Inc. — matched by CVE ID, not by vendor name.