CVE-2022-22965

critical

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

References

https://github.com/Vaibhav91one/spring4shell-cve-lab

https://github.com/Balckers/mcp-security-server

https://github.com/saaheerpurav/cve-twin

https://github.com/Induj1/cve-twin

https://github.com/lr-elaina520/cve-analysis

https://github.com/chengbochuan3/Security-Blog

https://github.com/chengbochuan3/CVE-Web-Framework

https://github.com/berinle/spring-enterprise-remediation-demo

https://github.com/ymad1/pgt-pipeline

https://github.com/brian-mitchell-sec/http-bait

https://github.com/CVEasy/cveasy-mcp

https://github.com/HaakimSec/zero2shell-50

https://github.com/balajiltechai/order-service

https://github.com/meng-security/spring4shell-local-verification-lab

https://github.com/umaadi/truepositive-cli

https://github.com/kokunas/java-app-cve

https://github.com/RootEvil333/CVE-2022-22965

https://github.com/panda12332145/cve-vulnerability-scanner

https://github.com/Kuri119/CVE-2022-22965-Spring4Shell

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/test-avm-714877d2df585126/dependabot-cve-test-2

https://github.com/test-avm-714877d2df585126/dependabot-cve-test

https://github.com/Lanexus/cve-scanner

https://github.com/ernestom-commits/jfrog-apptrust-demo

https://github.com/heyjerrybecker/seevie-pri

https://github.com/888irdy/cve-research

https://github.com/Sansyuh06/CVE-Guard

https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE

https://github.com/panaresh2007/osv-java-poc

https://github.com/march0n/PoC-CVE-2022-22965-Spring4Shell

https://github.com/YUTING-HUANG0/Spring4Shell-CTF

https://github.com/1392081456/sigma-detection-rules

https://github.com/BolajiEdu/cve-network-scanner

https://github.com/banaeye/cvetest

https://github.com/felisha-elmer/Sandbox-Challenge-Spring4Shell-CVE-2022-22965-

https://github.com/flags-alt/abyss-c2

https://github.com/preetideepaksoni/Penetration-Testing-Portfolio

https://github.com/aarondutton-grc/nist-nvd-cve-to-cwe-mapper

https://github.com/shaharyar0306/suricata-ips-autotuner

https://github.com/vogi-san/Vulnerability-AI-Assistant

https://github.com/neilc1964techned/craready-test-java-vulns

https://github.com/wyqsgy/vulnark

https://github.com/psyf8t/spring-security-rules

https://github.com/yashmoar11/RAG-poison

https://github.com/dbwlsdnr95/CVE-Research

https://github.com/C4yberLan/SpringBoot-Exploit-Toolkit

https://github.com/nitishsancs/SecureScope

https://github.com/nitishsjsucs/SecureScope

https://github.com/palvevaibhav/cvecheck

https://github.com/Sansyuh06/CVE-Triage-Env

https://github.com/marvang/vuln-variants

https://github.com/KosmicOwl045/ICT287-CVE-2022-42889

https://github.com/plusive27-max/cve-lookup

https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner

https://github.com/glory903-devsecops/CVE-2022-22965

https://github.com/lizuyi-6/aetherguard-security-dataset

https://github.com/iosec-shekhar/COIT

https://github.com/zaryouhashraf/CVE-2022-22965

https://github.com/0xAshwesker/CVE-2022-22965

https://github.com/donghass/CVE-Vulnerability-analysis-reports

https://github.com/venubhamidi/concert-cve-demo

https://github.com/lightman-gg/opencve

https://github.com/SimoesCTT/CTT-enhanced-VMware-vCenter

https://github.com/SimoesCTT/CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Exploit

https://github.com/suyash-R-K/dfir-malware-investigation

https://github.com/seol1013/CVE

https://github.com/8BitTacoSupreme/sbom_CVE_dash_demo

https://github.com/Syedomershah99/CVE-semantic-IEEE

https://github.com/Anon2Fear/CVE-2022-22965

https://github.com/nhattanhh/CVE-2022-22965

https://github.com/tinashelorenzi/CVE-2025-55182

https://github.com/Hghost0x00/CVE-2022-22965

https://github.com/clay-good/blastauri

https://github.com/Karararam/SpringBoot-Exploit-Toolkit

https://github.com/ledigiacomo/InterviewCVEExercise

https://github.com/mylo-2001/GhostStrike

https://github.com/Toph404/telstra-cyber-analyst-job-simulation

https://github.com/vBarbaros/security-faux-pas

https://github.com/V0idA2tronaut/CVEs

https://github.com/junwonheo/cve-analysis

https://github.com/mayank1120/cve-fix-checker

https://github.com/salo-404/firewall

https://github.com/gnlds/mcp-cve-intelligence-server-lite

https://github.com/Nosie12/fire-wall-server

https://github.com/ZTheH/netmap

https://github.com/altjerry0/seevee

https://github.com/schinniachari/genai

https://github.com/brunoh6/web-threat-mitigation

https://github.com/tim3959951/CVE-Analysis-Agent

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/Chrisync/CVE-Scanner

https://github.com/jashan-lefty/Spring4Shell

https://github.com/guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965

https://github.com/kdandy/devtools

https://github.com/ucsb-seclab/CVEX-records

https://github.com/abozzoni/cve-app

https://github.com/auditor-kbfg/CVE_Scanner

https://github.com/charonlight/SpringExploitGUI

https://github.com/h4ck0rman/Spring4Shell-PoC

https://github.com/gokul-ramesh/Spring4Shell-PoC-exploit

https://github.com/zangcc/CVE-2022-22965-rexbb

https://github.com/iloveflag/Fast-CVE-2022-22965

https://github.com/lolminerxmrig/Capricornus

https://github.com/D1mang/Spring4Shell-CVE-2022-22965

https://github.com/tpt11fb/SpringVulScan

https://github.com/p1ckzi/CVE-2022-22965

https://github.com/0zvxr/CVE-2022-22965

https://github.com/Loneyers/Spring4Shell

https://github.com/4nth0ny1130/spring4shell_behinder

https://github.com/alt3kx/CVE-2022-22965

https://github.com/wyunan/CVE-Details

https://github.com/datawiza-inc/spring-rec-demo

https://github.com/Snip3R69/spring-shell-vuln

https://github.com/anair-it/springshell-vuln-POC

https://github.com/daniel0x00/Invoke-CVE-2022-22965-SafeCheck

https://github.com/gpiechnik2/nmap-spring4shell

https://github.com/wjl110/CVE-2022-22965_Spring_Core_RCE

https://github.com/wshon/spring-framework-rce

https://github.com/zer0yu/CVE-2022-22965

https://github.com/Joe1sn/CVE-2022-22965

https://github.com/whoami0622/CVE-2022-22965-POC

https://github.com/iwarsong/CVE-2022-22965-POC

https://github.com/chaosec2021/CVE-2022-22965-POC

https://github.com/tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce

https://github.com/Axx8/SpringFramework_CVE-2022-22965_RCE

https://github.com/likewhite/CVE-2022-22965

https://github.com/mebibite/springhound

https://github.com/advisories/GHSA-36p3-wjmg-h94x

https://github.com/GuayoyoCyber/CVE-2022-22965

https://github.com/liangyueliangyue/spring-core-rce

https://github.com/k3rwin/spring-core-rce

https://github.com/DDuarte/springshell-rce-poc

https://github.com/light-Life/CVE-2022-22965-GUItools

https://github.com/CnHack3r/Awesome-hacking-tools

https://github.com/XuCcc/VulEnv

https://www.kb.cert.org/vuls/id/970766

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965

https://tanzu.vmware.com/security/cve-2022-22965

http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2022-04-01

Updated: 2026-06-17

Named Vulnerability: SpringShellNamed Vulnerability: Spring4ShellKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99638