CVE-2024-46983Patch(antfin / sofa-hessian)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch antfin sofa-hessian systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components. This issue is fixed by an update to the blacklist, users can upgrade to sofahessian version 3.5.5 to avoid this issue. Users unable to upgrade may maintain a blacklist themselves in the directory `external/serialize.blacklist`.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sofa-hessian

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
sofa-hessian

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 104-14
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Patch

    A Remote Command Execution (RCE) vulnerability (CVE-2024-46983) affects `SOFA Hessian`. Systems deserializing untrusted `Hessian` data are at risk. Await official patches. #RCE #Deserialization #Infosec https://www.pulsepatch.io/posts/cve-2024-46983-sofa-hessian-rce-vulnerability

    Post summary

    The post highlights CVE‑2024‑46983, a Remote Command Execution flaw in SOFA Hessian that could affect systems deserializing untrusted Hessian data, and urges waiting for official patches.

    0000050
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appantfinsofa-hessian---

Explore more