August 9, 2026 August 9, 2026 Fastjson 1.x 终局之战:CVE-2026-16723 无 Gadget RCE 深度分析 fastjson 1.2.68–1.2.83 全线沦陷:无需开启 AutoType、无需 classpath gadget,默认配置即可远程代码执行。本文从 checkAutoType 的资源探测缺陷出发,完整拆解 @JSONType 信任绕过与 /proc/self/fd 攻击链,并给出可落地的修复方案。 REC SecurityJavaFastjson