GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
https://www.suse.com/support/shellshock/
https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075
https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html
https://support.citrix.com/article/CTX200217
https://support.apple.com/kb/HT6535
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648
http://www.vmware.com/security/advisories/VMSA-2014-0010.html
http://www.us-cert.gov/ncas/alerts/TA14-268A
http://www.ubuntu.com/usn/USN-2362-1
http://www.qnap.com/i/en/support/con_show.php?cid=61
http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html
http://www.novell.com/support/kb/doc.php?id=7015721
http://www.novell.com/support/kb/doc.php?id=7015701
http://www.mandriva.com/security/advisories?name=MDVSA-2015:164
http://www.kb.cert.org/vuls/id/252743
http://www.debian.org/security/2014/dsa-3032
http://www-01.ibm.com/support/docview.wss?uid=swg21687079
http://www-01.ibm.com/support/docview.wss?uid=swg21686494
http://www-01.ibm.com/support/docview.wss?uid=swg21686447
http://www-01.ibm.com/support/docview.wss?uid=swg21686445
http://www-01.ibm.com/support/docview.wss?uid=swg21686246
http://www-01.ibm.com/support/docview.wss?uid=swg21686131
http://www-01.ibm.com/support/docview.wss?uid=swg21686084
http://www-01.ibm.com/support/docview.wss?uid=swg21685749
http://www-01.ibm.com/support/docview.wss?uid=swg21685733
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
http://www-01.ibm.com/support/docview.wss?uid=swg21685541
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279
http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash
https://www.exploit-db.com/exploits/42938/
https://www.exploit-db.com/exploits/40938/
https://www.exploit-db.com/exploits/40619/
https://www.exploit-db.com/exploits/39918/
https://www.exploit-db.com/exploits/38849/
https://github.com/Vaibhav91one/shellshock-cve-lab
https://github.com/Sudo-Zaid/cve-poc-writeups
https://github.com/FREEGUY-6/dmz-security-monitoring-hardening
https://github.com/MrEchoFi/docklab
https://github.com/Athology0000/cve-lab
https://github.com/sudichai/cve-destroyer
https://github.com/Kushiro45/shellshock-poc-cve-2014-7169
https://github.com/caverm/Shellshock_CVE-2014-6271
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/fDarkShadow/noctis
https://github.com/pro-pankaj-pentester/cve-writeups-50000
https://github.com/krish-achanta/vuln-validator
https://github.com/alexgar207/Shellshock-Attack-CVE--2014-6271-
https://github.com/FacundoMfernandez/-pentesting-obioba
https://github.com/HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-Thor
https://github.com/mrjoker-web/ShadowCVE
https://github.com/im2nerd/CVE-2014-6271
https://github.com/V3nG4mxV1p3r/Mobile-Drop-Device-SOC-Detection
https://github.com/kaleth4/CVE-2014-6271
https://github.com/kaleth4/-CVE-2014-6271
https://github.com/phantom-offensive/AppAssault
https://github.com/ambjlou/it355-lab4-enterprise-lan-security
https://github.com/phantom-offensive/AppAssaultLab
https://github.com/Phantom-C2-77/AppAssaultLab
https://github.com/adk86/CVE-Vulnerability-Research-Exploit-Analysis
https://github.com/0xAshwesker/CVE-2014-6271
https://github.com/Npg-1/CVE_Website
https://github.com/CVE-ORG/CVE-ORG
https://github.com/Arthurfert/SecLLM-Gen
https://github.com/N00BCYB0T/web-exploit-lab
https://github.com/N00BCYB0T/CVE-exploits
https://github.com/Noxpy/Noxpy
https://github.com/0xMarturano/Noxpy
https://github.com/imadm01/pentesting-lab-reports
https://github.com/mtaha-sec/bash-apocalypse
https://github.com/DrHaitham/CVE-2014-6271-Shellshock-
https://github.com/uttambodara/Awesome-Hacking-Learning-Path
https://github.com/RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
https://github.com/cyberleelawat/LeelawatX-CVE-Hunter
https://github.com/h4r1337/cve-labs
https://github.com/phntmzn/sound-scan
https://github.com/jlucas8/cve-test-scripts
https://github.com/moften/CVE-2014-6271
https://github.com/YunchoHang/CVE-2014-6271-SHELLSHOCK
https://github.com/David-Ogrande/CVEs-NVD
https://github.com/RadYio/CVE-2014-6271
https://github.com/ucsb-seclab/CVEX-records
https://github.com/TheRealCiscoo/Shellshock
https://github.com/TheRealCiscoo/Shellshock-Exploit
https://github.com/hackintoanetwork/shellshock
https://github.com/0xget/cve-2001-1473
https://github.com/0xN7y/CVE-2014-6271
https://github.com/Darkrai-404/Penetration-Testing-Writeups
https://github.com/0bfxgh0st/cve-rebuilds
https://github.com/KJOONHWAN/CVE-Exploit-Demonstration
https://github.com/vulhub/vulhub
https://github.com/FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-
https://github.com/anujbhan/shellshock-victim-host
https://github.com/Gurguii/shellshock.sh
https://github.com/Gurguii/cgi-bin-shellshock
https://github.com/hadrian3689/shellshock
https://github.com/abandonedship/ShellShock
https://github.com/0bfxgh0st-secondary/ShellShock
https://github.com/aphiliotis1/ShellShock
https://github.com/JowardBince/ShellShock
https://github.com/JBince/ShellShock
https://github.com/0bfxgh0st/ShellShock
https://github.com/b4keSn4ke/shellshock
https://github.com/somhm-solutions/Shell-Shock
https://github.com/heikipikker/shellshock-shell
https://github.com/r4z0r5/SwissArmyShellshocker
https://github.com/P0cL4bs/ShellShock-CGI-Scan
https://github.com/sunnyjiang/shellshocker-android
https://github.com/352926/shellshock_crawler
https://github.com/akiraaisha/shellshocker-python
https://github.com/ramnes/pyshellshock
https://github.com/indiandragon/Shellshock-Vulnerability-Scan
https://github.com/renanvicente/puppet-shellshock
https://github.com/cj1324/CGIShell
https://github.com/proclnas/ShellShock-CGI-Scan
https://github.com/francisck/shellshock-cgi
https://github.com/x2c3z4/shellshock_crawler
https://github.com/pwnGuy/shellshock-shell
https://github.com/teedeedubya/bash-fix-exploit
https://github.com/APSL/salt-shellshock
https://github.com/ksang/shellshock
https://github.com/themson/shellshock
https://github.com/ariarijp/vagrant-shellshock
https://github.com/gabemarshall/shocknaww
https://github.com/RainMak3r/Rainstorm
https://github.com/ilismal/Nessus_CVE-2014-6271_check
https://github.com/justzx2011/bash-up
https://github.com/scottjpack/shellshock_scanner
https://github.com/jblaine/cookbook-bash-CVE-2014-6271
https://github.com/ryancnelson/patched-bash-4.3
https://github.com/npm/ansible-bashpocalypse
https://github.com/dlitz/bash-cve-2014-6271-fixes
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6271
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183
https://support.citrix.com/article/CTX200223
https://kc.mcafee.com/corporate/index?page=content&id=SB10085
https://kb.bluecoat.com/index?page=content&id=SA82
https://bugzilla.redhat.com/show_bug.cgi?id=1141597
https://access.redhat.com/node/1200223
https://access.redhat.com/articles/1200223
http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
http://www.securityfocus.com/bid/70103
http://www.securityfocus.com/archive/1/533593/100/0/threaded
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315
http://www-01.ibm.com/support/docview.wss?uid=swg21686479
Published: 2014-09-24
Updated: 2026-06-17
Named Vulnerability: ShellshockNamed Vulnerability: ShellShockNamed Vulnerability: Bash BugKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99999