Fastjson 1.2.68–1.2.83 is exploited with no AutoType and no gadgets. What gates it: Spring Boot executable fat-JAR, SafeMode off, and Object/Map fields in your DTO.
Two CRLF-adjacent bugs, two different checks. Smuggling is a proxy↔Tomcat HTTP/1.1 framing mismatch (tomcat-embed-core version, CVE-2026-24880); splitting is CRLF in sendRedirect/setHeader/RestTemplate. With a grep checklist.