CVE-2017-20227Disclosure(varaneckas / jad_java_decompiler)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a return-oriented programming chain that spawns a shell.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jad_java_decompiler

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-28); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
jad_java_decompiler

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-29: 1Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-01: 1Technical Details · 2026-03-28: 2Technical Details · 2026-03-29: 1Technical Details · 2026-04-01: 103-2803-2904-01
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-282
Disclosure2
2026-03-291
General1
2026-04-011
PoC1
Full discourse4 posts
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2017-20227: JAD 1.5.8e-1kali1 Stack-Based Bu... Ancient JAD decompiler's stack overflow is ROP-ready with public exploits - perfect for backdooring reverse engineering... https://zerodaysignal.com/vulnerability/CVE-2017-20227 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2017‑20227 is a stack‑based overflow in the JAD decompiler with publicly available exploits, but no patch or active exploitation details are provided.

    0000073
    194 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2017-20227 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-20227 #CVE-2017-20227 #CVE #Critical #CyberSecurity #InfoSec https://t.co/OD7Douofyp

    Post summary

    The tweet simply alerts about a high‑severity CVE-2017-20227 with minimal technical details and no exploitation or mitigation information.

    0000038
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2017-20227 JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly l… https://www.cve.org/CVERecord?id=CVE-2017-20227

    Post summary

    The post reports a stack-based buffer overflow in JAD Java Decompiler (v1.5.8e-1kali1 and earlier) that could lead to arbitrary code execution. No PoC, exploit, or patch details are provided.

    0000065
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2017-20227: CRITICAL] JAD Java Decompiler 1.5.8e-1kali1 and earlier versions have a stack-based buffer overflow vulnerability. Attackers can execute code by providing excessive input, triggering a malic...#cve,CVE-2017-20227,#cybersecurity https://cvefind.com/CVE-2017-20227

    Post summary

    The post announces a stack‑based buffer overflow in JAD Java Decompiler 1.5.8e‑1kali1 and earlier, allowing attackers to execute code via excessive input.

    0000042
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvaraneckasjad_java_decompiler1.5.8e-1kali1--

Explore more