Docker lab + one-payload exploit + defensive scanner for the fastjson 1.2.66-1.2.83 @jsontype remote-class-load RCE (SSRF->defineClass under Spring Boot LaunchedURLClassLoader; autoType OFF; parseObject binding is not a mitigation)
-
Updated
Jul 22, 2026 - Python