StackRadar

CVE-2026-16723

Critical

Advisory

Published 23 Jul 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.0
base score, highest
EPSS
0.160
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
None
affected package

fastjson has a remote code execution (RCE) vulnerability

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
fastjsonmaven1.2.69_noneautotype, 1.2.70, 1.2.73, 1.2.75+2 moreno fix listed17
OSV records
GHSA-crf3-v9rr-v7hj

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
rocketmqrocketmq12.6.02 of 2See more

rocketmq rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
fastjson@1.2.83
no fix listed
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
fastjson@1.2.83
no fix listed

Open the chart page →

6,328
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
fastjson@1.2.83
no fix listed

Open the chart page →

14,000
rocketmqgin1.1.02 of 2See more

rocketmq gin 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
fastjson@1.2.76
no fix listed
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
fastjson@1.2.76
no fix listed

Open the chart page →

9,154
rocketmq-clusterrocketmq12.6.02 of 2See more

rocketmq-cluster rocketmq 12.6.0

2 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
fastjson@1.2.83
no fix listed
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
fastjson@1.2.83
no fix listed

Open the chart page →

6,328
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
fastjson@1.2.73
no fix listed

Open the chart page →

5,624
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
fastjson@1.2.75
no fix listed

Open the chart page →

4,287
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
fastjson@1.2.83
no fix listed

Open the chart page →

8,001
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
no fix listed

Open the chart page →

12,513
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
fastjson@1.2.83
no fix listed

Open the chart page →

4,921
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
fastjson@1.2.83
no fix listed

Open the chart page →

4,664
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
fastjson@1.2.75
no fix listed

Open the chart page →

10,264
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
fastjson@1.2.83
no fix listed

Open the chart page →

6,490
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
fastjson@1.2.69_noneautotype
no fix listed

Open the chart page →

6,634
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
fastjson@1.2.83
no fix listed

Open the chart page →

1,995
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
fastjson@1.2.83
no fix listed

Open the chart page →

4,245
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
fastjson@1.2.83
no fix listed

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
no fix listed

Open the chart page →

12,513
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-16723.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
no fix listed

Open the chart page →

12,513

Container images carrying it

17 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
no fix listed
3
apache/rocketmq:5.4.0319cd8a81ed1
fastjson@1.2.83
no fix listed
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
fastjson@1.2.83
no fix listed
2
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
fastjson@1.2.83
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
fastjson@1.2.83
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
fastjson@1.2.83
no fix listed
1
apache/rocketmq:4.9.35ac2a4e0f627
fastjson@1.2.76
no fix listed
1
apache/rocketmq-exporter:0.0.2c8fb51195444
fastjson@1.2.69_noneautotype
no fix listed
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
fastjson@1.2.76
no fix listed
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
fastjson@1.2.83
no fix listed
1
kubebb/gateway-api:v5.6.04d062f20309c
fastjson@1.2.83
no fix listed
1
kubebb/mesh-api:v5.7.0a3879931dfa1
fastjson@1.2.83
no fix listed
1
refar/apm-api:v5.7.1241373fa2972
fastjson@1.2.75
no fix listed
1
royalwang/sentinel-dashboard:1.8.4df99e2499f91
fastjson@1.2.75
no fix listed
1
seataio/seata-server:latest703b5de7f1a6
fastjson@1.2.83
no fix listed
1
seataio/seata-server:1.5.1ee1ed55f4144
fastjson@1.2.73
no fix listed
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
fastjson@1.2.83
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.