Alibaba's Fastjson 1.x library carries a critical deserialization flaw that attackers are exploiting in Spring Boot applications.