Home/Product/hutool
Product

hutool

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-56769
< 5.8.40
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbi
6.5MEDIUM
CVE-2023-51080
>= 5.8.22 and < 5.8.25
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
7.5HIGH
CVE-2023-51075
< 5.8.24
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows
7.5HIGH
CVE-2023-42278
all versions
hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().
7.5HIGH
CVE-2023-42277
all versions
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
9.8CRITICAL
CVE-2023-42276
< 5.8.22
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
9.8CRITICAL
CVE-2023-3276
<= 5.8.19
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the
5.5MEDIUM
CVE-2023-33695
<= 5.8.17
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function
7.1HIGH
CVE-2023-24163
< 5.8.21
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engi
9.8CRITICAL
CVE-2023-24162
all versions
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXm
9.8CRITICAL
CVE-2022-4565
<= 5.8.10
A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the
4.3MEDIUM
CVE-2022-45690
< 5.8.11
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to caus
7.5HIGH
CVE-2022-45689
all versions
hutool-json v5.8.10 was discovered to contain an out of memory error.
7.5HIGH
CVE-2022-45688
all versions
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via
7.5HIGH
CVE-2022-22885
all versions
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
9.8CRITICAL
CVE-2018-17297
< 4.1.12
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory trav
7.5HIGH
threatengine.sh