In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
https://www.infosecurity-magazine.com/news/php-servers-and-iot-devices-cyber/
https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
https://www.wiz.io/blog/spring-boot-actuator-misconfigurations
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://github.com/lr-elaina520/cve-analysis
https://github.com/Athology0000/cve-lab
https://github.com/HaakimSec/zero2shell-50
https://github.com/ciri3/spring-cloud-gateway-cve-2022-22947-report
https://github.com/wyqsgy/vulnark
https://github.com/psyf8t/spring-security-rules
https://github.com/C4yberLan/SpringBoot-Exploit-Toolkit
https://github.com/SanderSchepers1993/CyberSec2026
https://github.com/Karararam/SpringBoot-Exploit-Toolkit
https://github.com/skysliently/CVE-2022-22947-pb-ai
https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks
https://github.com/charonlight/SpringExploitGUI
https://github.com/Zh0um1/CVE-2022-22947
https://github.com/Whoopsunix/PPPVULNS
https://github.com/B0rn2d/Spring-Cloud-Gateway-Nacos
https://github.com/tpt11fb/SpringVulScan
https://github.com/stayfoolish777/CVE-2022-22947-POC
https://github.com/0730Nophone/CVE-2022-22947-
https://github.com/whwlsfb/cve-2022-22947-godzilla-memshell
https://github.com/zhizhuoshuma/Burp_VulPscan
https://github.com/F6JO/Burp_VulPscan
https://github.com/aesm1p/CVE-2022-22947-POC-Reproduce
https://github.com/talentsec/Spring-Cloud-Gateway-CVE-2022-22947
https://github.com/sagaryadav8742/springcloudRCE
https://github.com/viemsr/spring_cloud_gateway_memshell
https://github.com/Wrin9/CVE-2022-22947
https://github.com/k3rwin/spring-cloud-gateway-rce
https://github.com/Arrnitage/CVE-2022-22947_exp
https://github.com/Arrnitage/CVE-2022-22947-exp
https://github.com/An0th3r/CVE-2022-22947-exp
https://github.com/aodsec/CVE-2022-22947
https://github.com/mrknow001/CVE-2022-22947
https://github.com/YutuSec/SpEL
https://github.com/hunzi0/CVE-2022-22947-Rce_POC
https://github.com/Xd-tl/CVE-2022-22947-Rce_POC
https://github.com/nanaao/CVE-2022-22947-POC
https://github.com/chaosec2021/CVE-2022-22947-POC
https://github.com/debug4you/CVE-2022-22947
https://github.com/dbgee/CVE-2022-22947
https://github.com/awsassets/CVE-2022-22947-RCE
https://github.com/helloexp/CVE-2022-22947
https://github.com/advisories/GHSA-3gx9-37ww-9qw6
https://github.com/Tas9er/SpringCloudGatewayRCE
https://github.com/wjl110/Spring_CVE_2022_22947
https://github.com/Axx8/CVE-2022-22947_Rce_Exp
https://github.com/Vulnmachines/spring-cve-2022-22947
https://github.com/shakeman8/CVE-2022-22947-RCE
https://github.com/lucksec/Spring-Cloud-Gateway-CVE-2022-22947
https://github.com/XuCcc/VulEnv
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22947
https://tanzu.vmware.com/security/cve-2022-22947
http://packetstormsecurity.com/files/168742/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.html
http://packetstormsecurity.com/files/166219/Spring-Cloud-Gateway-3.1.0-Remote-Code-Execution.html