CVE-2014-6271
KEVHIGH 10.0EPSS 100.0%
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-01-28
- Nuclei
- critical · CWE-78
- Published
- 2014-09-24
- Updated
- 2025-10-22
Proof-of-concept exploits (94)
- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html
- http://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Sh…
- https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-c…
- https://www.exploit-db.com/exploits/34879/
- https://www.exploit-db.com/exploits/37816/
- https://www.exploit-db.com/exploits/40619/
- 0x00-0x00/CVE-2014-62713★ · 2017-11-23
- 0xN7y/CVE-2014-62711★ · 2023-10-31
- AlissoftCodes/Shellshock0★ · 2024-07-02
- AlissonFaoli/Shellshock0★ · 2024-07-02
- Anklebiter87/Cgi-bin_bash_Reverse1★ · 2017-10-30
- Any3ite/CVE-2014-62711★ · 2020-01-06
- Aruthw/CVE-2014-62710★ · 2018-07-18
- BluHExH/Hex-exploshop-vip1★ · 2025-05-24
- Brandaoo/CVE-2014-62710★ · 2023-03-29
- Dilith006/CVE-2014-62710★ · 2020-05-12
- DrPandemic/RBE2★ · 2014-10-04
- EvolvingSysadmin/Shellshock1★ · 2022-06-30
- FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-0★ · 2022-09-09
- HttpEduardo/ShellTHEbest0★ · 2026-01-08
- Jsmoreira02/CVE-2014-62715★ · 2024-09-22
- K3ysTr0K3R/CVE-2014-6271-EXPLOIT4★ · 2024-05-18
- KJOONHWAN/CVE-Exploit-Demonstration0★ · 2023-01-05
- Kaizhe/attacker1★ · 2021-01-04
- MuirlandOracle/CVE-2014-6271-IPFire0★ · 2020-11-25
- Pilou-Pilou/docker_CVE-2014-6271.0★ · 2017-01-25
- RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis0★ · 2025-08-09
- RadYio/CVE-2014-62711★ · 2024-11-26
- RainMak3r/Rainstorm2★ · 2014-09-26
- Sindadziy/cve-2014-62710★ · 2019-11-12
- Sindayifu/CVE-2019-14287-CVE-2014-62710★ · 2020-01-08
- TheRealCiscoo/Shellshock1★ · 2026-07-12
- TheRealCiscoo/Shellshock-Exploit1★ · 2026-05-16
- UMDTERPS/Shell-Shock-Update0★ · 2014-12-17
- Xandevistan/CVE-Exploit-Demonstration0★ · 2023-01-05
- YunchoHang/CVE-2014-6271-SHELLSHOCK0★ · 2025-02-26
- akr3ch/CVE-2014-62714★ · 2022-04-02
- andrewxx007/MyExploit-ShellShock1★ · 2023-05-15
- b4keSn4ke/CVE-2014-627115★ · 2022-04-01
- battleofthebots/decepticon0★ · 2023-10-13
- bdisann/ehmylist0★ · 2021-07-22
- capture0x/XSHOCK88★ · 2022-12-08
- cj1324/CGIShell13★ · 2014-10-02
- crinadeac/folder0★ · 2025-02-24
- criticalstack/bro-scripts72★ · 2021-11-17
- cved-sources/cve-2014-62710★ · 2021-04-15
- cyberharsh/Shellbash-CVE-2014-62710★ · 2020-08-15
- eduardo-paim/ShellTHEbest0★ · 2026-01-08
- ehackify/shockpot0★ · 2022-06-03
- hanmin0512/CVE-2014-6271_pwnable0★ · 2023-08-29
- heikipikker/shellshock-shell0★ · 2014-11-28
- hmlio/vaas-cve-2014-627122★ · 2019-10-08
- huanlu/cve-2014-6271-huan-lu0★ · 2015-06-10
- ibrahimAlbadrani/HTB_Shocker0★ · 2025-05-24
- internero/debian-lenny-bash_3.2.52-cve-2014-62710★ · 2014-09-26
- jblaine/cookbook-bash-CVE-2014-62710★ · 2014-09-25
- kelleykong/cve-2014-6271-mengjia-kong0★ · 2015-06-06
- knightc0de/Shellshock_vuln_Exploit0★ · 2025-06-21
- kowshik-sundararajan/CVE-2014-62710★ · 2018-05-04
- kxcode/kbash2★ · 2018-12-11
- mattclegg/CVE-2014-62710★ · 2014-09-25
- moayadalmalat/shellshock-exploit1★ · 2018-09-24
- mochizuki875/CVE-2014-6271-Apache-Debian1★ · 2021-10-06
- moften/CVE-2014-62710★ · 2025-05-05
- mrigank-9594/Exploit-Shellshock0★ · 2021-06-24
- mritunjay-k/CVE-2014-62710★ · 2023-03-02
- opsxcq/exploit-CVE-2014-6271231★ · 2023-05-11
- pbr94/Shellshock-Bash-Remote-Code-Execution-Vulnerability-and-Exploitation2★ · 2020-05-10
- rashmikadileeshara/CVE-2014-6271-Shellshock-0★ · 2020-05-12
- rrreeeyyy/cve-2014-6271-spec0★ · 2014-09-25
- rsherstnev/CVE-2014-62710★ · 2025-07-25
- rvolosatovs/mooshy0★ · 2018-05-06
- ryeyao/CVE-2014-6271_Test1★ · 2014-09-29
- sch3m4/RIS2★ · 2014-09-29
- securetiger/Exploit-Shellshock0★ · 2021-06-24
- securusglobal/BadBash4★ · 2014-09-26
- shawntns/exploit-CVE-2014-62710★ · 2019-04-28
- shaynewang/exploits0★ · 2017-11-16
- the-emmon/IPFire-RCE-exploit0★ · 2021-03-10
- villadora/CVE-2014-62710★ · 2014-09-26
- w4fz5uck5/ShockZaum-CVE-2014-62710★ · 2018-06-20
- woltage/CVE-2014-62710★ · 2014-09-26
- yanicklandry/bashfix0★ · 2014-09-26
- zalalov/CVE-2014-62714★ · 2017-04-30
- FacundoMfernandez/pentesting-obioba
- Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshock
- J0hnTh3Kn1ght/CVE-2014-6271
- TheRealCiscoo/shellshock-poc
- caverm/Shellshock_CVE-2014-6271
- im2sinister/CVE-2014-6271
- kaleth4/-CVE-2014-6271
- kaleth4/CVE-2014-6271
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (8)
- https://www.exploit-db.com/exploits/42938
- https://www.exploit-db.com/exploits/40938
- https://www.exploit-db.com/exploits/39918
- https://www.exploit-db.com/exploits/38849
- https://www.exploit-db.com/exploits/35115
- https://www.exploit-db.com/exploits/34900
- https://www.exploit-db.com/exploits/34896
- https://www.exploit-db.com/exploits/34895
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/bash-cve-2014-6271.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2014/CVE-2014-6271.yaml