📦 Hutool

by Hutool

🔍 What is Hutool?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-42276

CRITICAL CVSS 9.8 Sep 8, 2023

A buffer overflow vulnerability in hutool v5.8.21's jsonArray component allows attackers to execute arbitrary code or cause denial of service. This affects applications using vulnerable versions of th...

CVE-2022-22885

CRITICAL CVSS 9.8 Feb 16, 2022

CVE-2022-22885 is a critical vulnerability in Hutool v5.7.18 where the HttpRequest component disables TLS/SSL certificate validation, allowing man-in-the-middle attacks. This affects any application u...

CVE-2023-51075

HIGH CVSS 7.5 Dec 27, 2023

CVE-2023-51075 is an infinite loop vulnerability in hutool-core's StrSplitter.splitByRegex function that allows attackers to cause Denial of Service (DoS) by manipulating input parameters. This affect...

CVE-2023-51080

HIGH CVSS 7.5 Dec 27, 2023

A stack overflow vulnerability in hutool-core's NumberUtil.toBigDecimal method allows attackers to cause denial of service by providing specially crafted input. This affects applications using vulnera...

CVE-2023-42278

HIGH CVSS 7.5 Sep 8, 2023

CVE-2023-42278 is a buffer overflow vulnerability in hutool's JSONUtil.parse() function that could allow attackers to execute arbitrary code or cause denial of service. This affects applications using...

CVE-2023-33695

HIGH CVSS 7.1 Jun 13, 2023

Hutool versions 5.8.17 and below contain an information disclosure vulnerability where the File.createTempFile() function in FileUtil.java creates temporary files with insecure permissions. This allow...

CVE-2025-56769

MEDIUM CVSS 6.5 Sep 25, 2025

A vulnerability in chinabugotech hutool's QLExpressEngine class allows attackers to execute arbitrary expressions, leading to arbitrary method invocation and potential remote code execution. This affe...