PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9497 changmingxie CVE debrief

A deserialization vulnerability exists in tcc-transaction versions up to 2.1.0, specifically within the Fastjson.parseObject function used by the Fastjson AutoType REST API component. The vulnerability allows remote attackers to trigger deserialization attacks. The CVSS 4.0 score of 2.1 reflects LOW severity with network attack vector, low attack complexity, and low impacts to confidentiality, integrity, and availability. The vendor was contacted prior to disclosure but did not respond. The CVE was published on 2026-05-25 and modified on 2026-05-26. The vulnerability is associated with CWE-20 (Improper Input Validation) and CWE-502 (Deserialization of Untrusted Data).

Vendor
changmingxie
Product
tcc-transaction
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-07-23
Advisory published
2026-05-25
Advisory updated
2026-07-23

Who should care

Organizations running tcc-transaction versions up to 2.1.0 with Fastjson AutoType enabled in REST API configurations. Development teams using Fastjson with AutoType in Java applications. Security teams monitoring for deserialization vulnerabilities in transaction management frameworks.

Technical summary

The vulnerability stems from unsafe deserialization in Fastjson's parseObject function when AutoType is enabled in the tcc-transaction framework. AutoType allows automatic type inference during JSON parsing, which can be exploited to instantiate arbitrary classes through crafted JSON payloads. The REST API exposure enables remote attack initiation. The CVSS 4.0 vector indicates network accessibility with low attack complexity but requires low privileges (PR:L), limiting the attack surface compared to unauthenticated vulnerabilities.

Defensive priority

low

Recommended defensive actions

  • Review and update tcc-transaction to a version newer than 2.1.0 if available, or apply vendor-provided patches when released.
  • Disable Fastjson AutoType functionality if not required, or restrict AutoType to an explicit allowlist of safe classes.
  • Implement input validation and sanitization for all data passed to Fastjson.parseObject in REST API endpoints.
  • Monitor for suspicious deserialization activity in application logs, particularly for unexpected class instantiation.
  • Consider migrating to alternative JSON libraries with safer default deserialization behavior if vendor patches are not forthcoming.
  • Apply network segmentation and access controls to limit exposure of affected REST API endpoints to untrusted networks.

Evidence notes

The vulnerability description is sourced from official CVE records and NVD data. The affected product is identified as changmingxie tcc-transaction up to version 2.1.0. The specific vulnerable component is the Fastjson AutoType REST API using Fastjson.parseObject.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9497 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9497

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9497 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9497

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.