GHSA-4r4v-3jc5-hrg9

Suggest an improvement
Source
https://github.com/advisories/GHSA-4r4v-3jc5-hrg9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-4r4v-3jc5-hrg9/GHSA-4r4v-3jc5-hrg9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4r4v-3jc5-hrg9
Aliases
  • CVE-2026-9497
Published
2026-05-26T13:30:50Z
Modified
2026-06-30T17:56:29Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
TCC-TRANSACTION has an Improper Input Validation vulnerability
Details

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids":  [
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-30T17:37:10Z",
    "nvd_published_at":  "2026-05-25T20:16:38Z",
    "severity":  "LOW"
}
References

Affected packages

Maven / org.mengyun:tcc-transaction

Package

Name
org.mengyun:tcc-transaction
View open source insights on deps.dev
Purl
pkg:maven/org.mengyun/tcc-transaction

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.1.0

Affected versions

2.*
2.0.0-alpha
2.0.0
2.0.1
2.0.2
2.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-4r4v-3jc5-hrg9/GHSA-4r4v-3jc5-hrg9.json"