[GHSA-prf8-cf2x-rhx7] fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE#7570
Open
brodmart wants to merge 1 commit intobrodmart/advisory-improvement-7570from
Commits
Commits on May 1, 2026
- committed