threedr3am/learnjavabug resource
Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。 observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3043
- days_rel: n/a
- days_push: 902
- n_releases_24m: 0
Adoption not part of the score
2687 stars · 493 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A collection of Java security vulnerability demos and exploit proof-of-concepts covering deserialization issues in libraries like Fast, Jackson, and Hessian2, plus exploits for frameworks and middleware such as Spring, Dubbo, Shiro, CAS, and Tomcat. It also includes Java Security Manager bypass techniques and security hardening examples, serving as the author's personal technical notes for security research.
Use cases
- reproduce fast deserialization RCE vulnerabilities
- learn jackson deserialization exploit gadgets
- study dubbo hessian2 deserialization attacks and hardening
- understand padding oracle CBC attacks in Java
- find exploit demos for Shiro and Spring middleware vulnerabilities
- learn Java Security Manager bypass techniques
- study SSRF and DNS lookup gadgets in JSON deserialization
When to choose
- you are a security researcher studying Java deserialization vulnerabilities
- you need reference PoC code for fast, jackson, or dubbo exploits
- you want to learn how middleware like Shiro, Tomcat, or CAS are exploited
- you need examples of Java security hardening like hessian2 blacklists
When to avoid
- you need a production security scanning tool
- you want automated vulnerability detection rather than manual demos
- you are not working with the Java/JVM ecosystem
- you intend to use exploits against systems without authorization
Facets
learning-resource · maturity active
security penetration-testing vulnerability-scanning reverse-engineering serialization security penetration-testing developer-tools tutorials jvm cross-platform java-security deserialization-vulnerabilities exploit-demos fast jackson dubbo shiro vulnerability-research security-research poc
1 source
- readme: https://github.com/threedr3am/learnjavabug · fetched 2026-08-28 · 00db78cac121
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| threedr3am/learnjavabug | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="threedr3am/learnjavabug")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem