Web Hack List

Preliminary research

Cast Attack: A New Threat Posed by Ghost Bits in Java

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

The Cast Attack exploits Java narrowing a 16-bit char to a byte (via (byte) ch and ch & 0xFF), dropping the high 8 bits ('ghost bits'). An attacker submits a Unicode character whose low byte equals a forbidden ASCII byte, so a WAF or validator sees harmless Unicode while the sink decodes the real payload. It demonstrates bypasses reaching SQLi, fastjson/Jackson deserialization, path traversal and auth bypass, SMTP injection, and HTTP CRLF request smuggling across many Java libraries.

Record

Researcher
Xinyu Bai and Zhihui Chen
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Xinyu Bai and Zhihui Chen, first published at the original source. Preserved copies are kept so the citation survives its host.