Hutool is a widely used Java utility library that abstracts common operations across diverse functional domains—file handling, serialization, encryption, and HTTP communication—making it a critical dependency in the Java ecosystem. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through memory-unsafe patterns and trust-boundary violations including out-of-bounds writes, buffer overflows, deserialization of untrusted data, certificate validation bypasses, and path-traversal flaws. The concentrated exposure in a single library that is embedded across numerous downstream applications means that a single Hutool flaw can propagate widely; defenders should prioritize this vendor's security updates and inventory applications that depend on it. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hutool over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24162CRITICAL Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter. | Jan 31, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-24163CRITICAL SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine. | Jan 31, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-22885CRITICAL Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation. | Feb 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-42277CRITICAL hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | Sep 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-42276CRITICAL hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. | Sep 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2018-17297HIGH The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive | Sep 21, 2018 | 7.5 | 26 | NO | NO |
CVE-2022-45688HIGH A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. | Dec 13, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45690HIGH A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XM | Dec 13, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-45689HIGH hutool-json v5.8.10 was discovered to contain an out of memory error. | Dec 13, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-56769MEDIUM An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote cod | Sep 25, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hutool.
Media articles that mention a CVE ID that affects a product developed by Hutool — matched by CVE ID, not by vendor name.