Ross ROSS = Recommend OSS · open-source software intelligence for agents

threedr3am/learnjavabug resource

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。 observed · 2026-08-28

github.com/threedr3am/learnjavabug · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3043
  • days_rel: n/a
  • days_push: 902
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2687 stars · 493 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jackson, and Hessian2, plus exploits for frameworks and middleware such as Spring, Dubbo, Shiro, CAS, and Tomcat. It also includes Java Security Manager bypass techniques and security hardening examples, serving as the author's personal technical notes for security research.

Use cases

  • reproduce fast deserialization RCE vulnerabilities
  • learn jackson deserialization exploit gadgets
  • study dubbo hessian2 deserialization attacks and hardening
  • understand padding oracle CBC attacks in Java
  • find exploit demos for Shiro and Spring middleware vulnerabilities
  • learn Java Security Manager bypass techniques
  • study SSRF and DNS lookup gadgets in JSON deserialization

When to choose

  • you are a security researcher studying Java deserialization vulnerabilities
  • you need reference PoC code for fast, jackson, or dubbo exploits
  • you want to learn how middleware like Shiro, Tomcat, or CAS are exploited
  • you need examples of Java security hardening like hessian2 blacklists

When to avoid

  • you need a production security scanning tool
  • you want automated vulnerability detection rather than manual demos
  • you are not working with the Java/JVM ecosystem
  • you intend to use exploits against systems without authorization

Facets

learning-resource · maturity active

security penetration-testing vulnerability-scanning reverse-engineering serialization security penetration-testing developer-tools tutorials jvm cross-platform java-security deserialization-vulnerabilities exploit-demos fast jackson dubbo shiro vulnerability-research security-research poc

1 source

Member repositories

RepositoryRoleHealth v2
threedr3am/learnjavabugmain32

For agents

markdown · JSON · MCP: product_card(name="threedr3am/learnjavabug")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem