Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution ...