Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hutool

First CVE: Sep 21, 2018Active for: 8 yearsTotal CVEs: 15
47.8
VTI Score
High

Hutool is a widely used Java utility library that abstracts common operations across diverse functional domains—file handling, serialization, encryption, and HTTP communication—making it a critical dependency in the Java ecosystem. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through memory-unsafe patterns and trust-boundary violations including out-of-bounds writes, buffer overflows, deserialization of untrusted data, certificate validation bypasses, and path-traversal flaws. The concentrated exposure in a single library that is embedded across numerous downstream applications means that a single Hutool flaw can propagate widely; defenders should prioritize this vendor's security updates and inventory applications that depend on it. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hutool over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2018
7 years ago
Most Recent CVE
Sep 25, 2025
302 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-24162CRITICAL
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
Jan 31, 20239.831NONO
CVE-2023-24163CRITICAL
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Jan 31, 20239.830NONO
CVE-2022-22885CRITICAL
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Feb 16, 20229.830NONO
CVE-2023-42277CRITICAL
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
Sep 8, 20239.829NONO
CVE-2023-42276CRITICAL
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
Sep 8, 20239.829NONO
CVE-2018-17297HIGH
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive
Sep 21, 20187.526NONO
CVE-2022-45688HIGH
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Dec 13, 20227.525NONO
CVE-2022-45690HIGH
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XM
Dec 13, 20227.524NONO
CVE-2022-45689HIGH
hutool-json v5.8.10 was discovered to contain an out of memory error.
Dec 13, 20227.524NONO
CVE-2025-56769MEDIUM
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote cod
Sep 25, 20256.523NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
60%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None14 (93.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hutool.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hutool — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hutool's Products

View all 2 CNAs →

Top CWEs