hutool records
15 published records for vendor hutool.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 73.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-295 Improper Certificate Validation1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-502 Deserialization of Untrusted Data1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-24163No exploit | SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.hutool · hutool · CWE-89 | Critical9.8 | — | 1.4% | Jan 31, 2023 |
39Monitor | CVE-2022-22885No exploit | Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.hutool · hutool · CWE-295 | Critical9.8 | — | 1.3% | Feb 16, 2022 |
39Monitor | CVE-2023-24162No exploit | Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parametehutool · hutool · CWE-502 | Critical9.8 | — | 1.3% | Jan 31, 2023 |
39Monitor | CVE-2023-42277No exploit | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.hutool · hutool · CWE-120 | Critical9.8 | — | 0.9% | Sep 8, 2023 |
39Monitor | CVE-2023-42276No exploit | hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.hutool · hutool · CWE-120 | Critical9.8 | — | 0.9% | Sep 8, 2023 |
31Monitor | CVE-2018-17297Proof of concept | The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequhutool · hutool · CWE-22 | High7.5 | — | 2.7% | Sep 21, 2018 |
30Monitor | CVE-2022-45688Proof of concept | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JShutool · hutool · CWE-787 | High7.5 | — | 1.2% | Dec 13, 2022 |
30Monitor | CVE-2022-45690No exploit | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denialhutool · hutool · CWE-787 | High7.5 | — | 1.0% | Dec 13, 2022 |
30Monitor | CVE-2022-4565No exploit | Dromara HuTool cn.hutool.core.util.ZipUtil.java resource consumptionhutool · hutool · CWE-404 | High7.5 | — | 0.9% | Dec 16, 2022 |
30Monitor | CVE-2023-42278No exploit | hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().hutool · hutool · CWE-120 | High7.5 | — | 0.8% | Sep 8, 2023 |
30Monitor | CVE-2022-45689No exploit | hutool-json v5.8.10 was discovered to contain an out of memory error.hutool · hutool · CWE-787 | High7.5 | — | 0.8% | Dec 13, 2022 |
30Monitor | CVE-2023-51075No exploit | hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function.hutool · hutool · CWE-835 | High7.5 | — | 0.7% | Dec 27, 2023 |
30Monitor | CVE-2023-51080No exploit | The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.hutool · hutool · CWE-787 | High7.5 | — | 0.6% | Dec 27, 2023 |
28Monitor | CVE-2023-33695No exploit | Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/ihutool · hutool · CWE-732 | High7.1 | — | 0.2% | Jun 13, 2023 |
26Monitor | CVE-2025-56769No exploit | An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary methhutool · hutool · CWE-77 | Medium6.5 | — | 0.3% | Sep 25, 2025 |
- CVE-2023-2416339Monitor
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
CriticalCVSS 9.8No exploitEPSS 1%hutool · hutoolJan 31, 2023
- CVE-2022-2288539Monitor
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
CriticalCVSS 9.8No exploitEPSS 1%hutool · hutoolFeb 16, 2022
- CVE-2023-2416239Monitor
Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml paramete
CriticalCVSS 9.8No exploitEPSS 1%hutool · hutoolJan 31, 2023
- CVE-2023-4227739Monitor
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.
CriticalCVSS 9.8No exploitEPSS 1%hutool · hutoolSep 8, 2023
- CVE-2023-4227639Monitor
hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.
CriticalCVSS 9.8No exploitEPSS 1%hutool · hutoolSep 8, 2023
- CVE-2018-1729731Monitor
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequ
HighCVSS 7.5Proof of conceptEPSS 3%hutool · hutoolSep 21, 2018
- CVE-2022-4568830Monitor
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JS
HighCVSS 7.5Proof of conceptEPSS 1%hutool · hutoolDec 13, 2022
- CVE-2022-4569030Monitor
A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolDec 13, 2022
- CVE-2022-456530Monitor
Dromara HuTool cn.hutool.core.util.ZipUtil.java resource consumption
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolDec 16, 2022
- CVE-2023-4227830Monitor
hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolSep 8, 2023
- CVE-2022-4568930Monitor
hutool-json v5.8.10 was discovered to contain an out of memory error.
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolDec 13, 2022
- CVE-2023-5107530Monitor
hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function.
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolDec 27, 2023
- CVE-2023-5108030Monitor
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.
HighCVSS 7.5No exploitEPSS 1%hutool · hutoolDec 27, 2023
- CVE-2023-3369528Monitor
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/i
HighCVSS 7.1No exploitEPSS 0%hutool · hutoolJun 13, 2023
- CVE-2025-5676926Monitor
An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary meth
MediumCVSS 6.5No exploitEPSS 0%hutool · hutoolSep 25, 2025