Product
hutool
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-56769
CVE-2023-51080
CVE-2023-51075
CVE-2023-42278
CVE-2023-42277
CVE-2023-42276
CVE-2023-3276
CVE-2023-33695
CVE-2023-24163
CVE-2023-24162
CVE-2022-4565
CVE-2022-45690
CVE-2022-45689
CVE-2022-45688
CVE-2022-22885
CVE-2018-17297
< 5.8.40
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbi
>= 5.8.22 and < 5.8.25
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
< 5.8.24
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows
all versions
hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().
all versions
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
< 5.8.22
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
<= 5.8.19
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the
<= 5.8.17
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function
< 5.8.21
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engi
all versions
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXm
<= 5.8.10
A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the
< 5.8.11
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to caus
all versions
hutool-json v5.8.10 was discovered to contain an out of memory error.
all versions
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via
all versions
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
< 4.1.12
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory trav