A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005
https://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdf
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://github.com/Vaibhav91one/spring4shell-cve-lab
https://github.com/Balckers/mcp-security-server
https://github.com/saaheerpurav/cve-twin
https://github.com/Induj1/cve-twin
https://github.com/lr-elaina520/cve-analysis
https://github.com/chengbochuan3/Security-Blog
https://github.com/chengbochuan3/CVE-Web-Framework
https://github.com/berinle/spring-enterprise-remediation-demo
https://github.com/ymad1/pgt-pipeline
https://github.com/brian-mitchell-sec/http-bait
https://github.com/CVEasy/cveasy-mcp
https://github.com/HaakimSec/zero2shell-50
https://github.com/balajiltechai/order-service
https://github.com/meng-security/spring4shell-local-verification-lab
https://github.com/umaadi/truepositive-cli
https://github.com/kokunas/java-app-cve
https://github.com/RootEvil333/CVE-2022-22965
https://github.com/panda12332145/cve-vulnerability-scanner
https://github.com/Kuri119/CVE-2022-22965-Spring4Shell
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/test-avm-714877d2df585126/dependabot-cve-test-2
https://github.com/test-avm-714877d2df585126/dependabot-cve-test
https://github.com/Lanexus/cve-scanner
https://github.com/ernestom-commits/jfrog-apptrust-demo
https://github.com/heyjerrybecker/seevie-pri
https://github.com/888irdy/cve-research
https://github.com/Sansyuh06/CVE-Guard
https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE
https://github.com/panaresh2007/osv-java-poc
https://github.com/march0n/PoC-CVE-2022-22965-Spring4Shell
https://github.com/YUTING-HUANG0/Spring4Shell-CTF
https://github.com/1392081456/sigma-detection-rules
https://github.com/BolajiEdu/cve-network-scanner
https://github.com/banaeye/cvetest
https://github.com/felisha-elmer/Sandbox-Challenge-Spring4Shell-CVE-2022-22965-
https://github.com/flags-alt/abyss-c2
https://github.com/preetideepaksoni/Penetration-Testing-Portfolio
https://github.com/aarondutton-grc/nist-nvd-cve-to-cwe-mapper
https://github.com/shaharyar0306/suricata-ips-autotuner
https://github.com/vogi-san/Vulnerability-AI-Assistant
https://github.com/neilc1964techned/craready-test-java-vulns
https://github.com/wyqsgy/vulnark
https://github.com/psyf8t/spring-security-rules
https://github.com/yashmoar11/RAG-poison
https://github.com/dbwlsdnr95/CVE-Research
https://github.com/C4yberLan/SpringBoot-Exploit-Toolkit
https://github.com/nitishsancs/SecureScope
https://github.com/nitishsjsucs/SecureScope
https://github.com/palvevaibhav/cvecheck
https://github.com/Sansyuh06/CVE-Triage-Env
https://github.com/marvang/vuln-variants
https://github.com/KosmicOwl045/ICT287-CVE-2022-42889
https://github.com/plusive27-max/cve-lookup
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/glory903-devsecops/CVE-2022-22965
https://github.com/lizuyi-6/aetherguard-security-dataset
https://github.com/iosec-shekhar/COIT
https://github.com/zaryouhashraf/CVE-2022-22965
https://github.com/0xAshwesker/CVE-2022-22965
https://github.com/donghass/CVE-Vulnerability-analysis-reports
https://github.com/venubhamidi/concert-cve-demo
https://github.com/lightman-gg/opencve
https://github.com/SimoesCTT/CTT-enhanced-VMware-vCenter
https://github.com/suyash-R-K/dfir-malware-investigation
https://github.com/seol1013/CVE
https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo
https://github.com/Syedomershah99/CVE-semantic-IEEE
https://github.com/Anon2Fear/CVE-2022-22965
https://github.com/nhattanhh/CVE-2022-22965
https://github.com/tinashelorenzi/CVE-2025-55182
https://github.com/Hghost0x00/CVE-2022-22965
https://github.com/clay-good/blastauri
https://github.com/Karararam/SpringBoot-Exploit-Toolkit
https://github.com/ledigiacomo/InterviewCVEExercise
https://github.com/mylo-2001/GhostStrike
https://github.com/Toph404/telstra-cyber-analyst-job-simulation
https://github.com/vBarbaros/security-faux-pas
https://github.com/V0idA2tronaut/CVEs
https://github.com/junwonheo/cve-analysis
https://github.com/mayank1120/cve-fix-checker
https://github.com/salo-404/firewall
https://github.com/gnlds/mcp-cve-intelligence-server-lite
https://github.com/Nosie12/fire-wall-server
https://github.com/ZTheH/netmap
https://github.com/altjerry0/seevee
https://github.com/schinniachari/genai
https://github.com/brunoh6/web-threat-mitigation
https://github.com/tim3959951/CVE-Analysis-Agent
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/Chrisync/CVE-Scanner
https://github.com/jashan-lefty/Spring4Shell
https://github.com/guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
https://github.com/kdandy/devtools
https://github.com/ucsb-seclab/CVEX-records
https://github.com/abozzoni/cve-app
https://github.com/auditor-kbfg/CVE_Scanner
https://github.com/charonlight/SpringExploitGUI
https://github.com/h4ck0rman/Spring4Shell-PoC
https://github.com/gokul-ramesh/Spring4Shell-PoC-exploit
https://github.com/zangcc/CVE-2022-22965-rexbb
https://github.com/iloveflag/Fast-CVE-2022-22965
https://github.com/lolminerxmrig/Capricornus
https://github.com/D1mang/Spring4Shell-CVE-2022-22965
https://github.com/tpt11fb/SpringVulScan
https://github.com/p1ckzi/CVE-2022-22965
https://github.com/0zvxr/CVE-2022-22965
https://github.com/Loneyers/Spring4Shell
https://github.com/4nth0ny1130/spring4shell_behinder
https://github.com/alt3kx/CVE-2022-22965
https://github.com/wyunan/CVE-Details
https://github.com/datawiza-inc/spring-rec-demo
https://github.com/Snip3R69/spring-shell-vuln
https://github.com/anair-it/springshell-vuln-POC
https://github.com/daniel0x00/Invoke-CVE-2022-22965-SafeCheck
https://github.com/gpiechnik2/nmap-spring4shell
https://github.com/wjl110/CVE-2022-22965_Spring_Core_RCE
https://github.com/wshon/spring-framework-rce
https://github.com/zer0yu/CVE-2022-22965
https://github.com/Joe1sn/CVE-2022-22965
https://github.com/whoami0622/CVE-2022-22965-POC
https://github.com/iwarsong/CVE-2022-22965-POC
https://github.com/chaosec2021/CVE-2022-22965-POC
https://github.com/tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce
https://github.com/Axx8/SpringFramework_CVE-2022-22965_RCE
https://github.com/likewhite/CVE-2022-22965
https://github.com/mebibite/springhound
https://github.com/advisories/GHSA-36p3-wjmg-h94x
https://github.com/GuayoyoCyber/CVE-2022-22965
https://github.com/liangyueliangyue/spring-core-rce
https://github.com/k3rwin/spring-core-rce
https://github.com/DDuarte/springshell-rce-poc
https://github.com/light-Life/CVE-2022-22965-GUItools
https://github.com/CnHack3r/Awesome-hacking-tools
https://github.com/XuCcc/VulEnv
https://www.kb.cert.org/vuls/id/970766
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965
https://tanzu.vmware.com/security/cve-2022-22965
http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html
Published: 2022-04-01
Updated: 2026-06-17
Named Vulnerability: SpringShellNamed Vulnerability: Spring4ShellKnown Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99638