build1 publisher
A Fastjson RCE walks in through the annotation check, not the type blacklist
CVE-2026-16723 fires against Fastjson 1.x with AutoType disabled and no known gadget class, because the @JSONType trust branch fetches an attacker-hosted class over HTTP just to read a metadata flag.
Publishers:dev.to
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence45