CVE-2022-22965
KEVCRITICAL 9.8EPSS 99.6%
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.64% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-04-04
- Nuclei
- critical · CWE-94
- Published
- 2022-04-01
- Updated
- 2025-10-21
Proof-of-concept exploits (122)
- http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html
- 0x801453/SpringbootGuiExploit20★ · 2024-06-07
- 0xr1l3s/CVE-2022-229650★ · 2022-04-05
- 0xrobiul/CVE-2022-229653★ · 2023-12-26
- 0zvxr/CVE-2022-2296523★ · 2022-06-30
- 24-2021/EXP-POC26★ · 2023-01-11
- Axx8/SpringFramework_CVE-2022-22965_RCE72★ · 2022-04-01
- BBD-YZZ/GUI-TOOLS25★ · 2024-05-28
- BKLockly/CVE-2022-229653★ · 2023-06-04
- BluHExH/Hex-exploshop-vip1★ · 2025-05-24
- BobTheShoplifter/Spring4Shell-POC376★ · 2022-11-09
- Bouquets-ai/CVE-2022-22965-GUItools17★ · 2022-04-02
- CalumHutton/CVE-2022-22965-PoC_Payara3★ · 2022-04-08
- D1mang/Spring4Shell-CVE-2022-229652★ · 2022-07-13
- DDuarte/springshell-rce-poc19★ · 2023-04-18
- Enokiy/spring-RCE-CVE-2022-229650★ · 2022-04-29
- FourCoreLabs/spring4shell-exploit-poc44★ · 2022-04-06
- GuayoyoCyber/CVE-2022-229656★ · 2022-04-19
- Gunavardhan-Naidu/Firewall_Server0★ · 2023-10-18
- HackJava/HackSpring47★ · 2022-04-26
- HackJava/Spring47★ · 2022-04-26
- Joe1sn/CVE-2022-229651★ · 2022-04-02
- Kirill89/CVE-2022-22965-PoC32★ · 2022-04-05
- LucasPDiniz/CVE-2022-229650★ · 2024-06-30
- LudovicPatho/CVE-2022-22965_Spring4Shell2★ · 2022-04-05
- MInggongK/SpringbootGuiExploit20★ · 2024-06-07
- Omaraitbenhaddi/-Spring4Shell-CVE-2022-22965-0★ · 2022-04-13
- PetrusViet/Poc-Spring4Shell-Jetty0★ · 2022-04-06
- Retrospected/spring-rce-poc86★ · 2022-03-31
- SeanWrightSec/spring-rce-poc4★ · 2022-04-07
- SecNN/SpringFramework_CVE-2022-22965_RCE72★ · 2022-04-01
- SheL3G/Spring4Shell-PoC1★ · 2022-12-03
- Sparrow-Co-Ltd/real_cve_examples1★ · 2024-04-12
- TheGejr/SpringShell131★ · 2022-04-04
- Wrin9/CVE-2022-229657★ · 2022-04-02
- ajith737/Spring4Shell-CVE-2022-22965-POC0★ · 2023-01-03
- anair-it/springshell-vuln-POC3★ · 2022-04-04
- avergnaud/spring4shell-intro0★ · 2022-04-10
- basu1706/590JFinalProject0★ · 2022-05-04
- bowwowxx/spring4Shell2★ · 2022-04-02
- c33dd/CVE-2022-229650★ · 2023-02-28
- c4mx/CVE-2022-22965_PoC1★ · 2022-04-21
- chaosec2021/EXP-POC26★ · 2023-01-11
- clemoregan/SSE4-CVE-2022-229651★ · 2022-11-28
- colincowie/Safer_PoC_CVE-2022-2296544★ · 2022-05-27
- cxzero/CVE-2022-22965-spring4shell1★ · 2023-12-21
- cybersecurityworks553/spring4shell-exploit7★ · 2023-03-30
- daniel0x00/Invoke-CVE-2022-22965-SafeCheck1★ · 2022-04-04
- devengpk/CVE-2022-229650★ · 2022-12-16
- dylanmo-jfrog/dgs-skeleton0★ · 2025-09-19
- edsonjt81/spring4shell0★ · 2022-05-11
- elijah-g-14/Spring4Shell-Demo0★ · 2022-10-31
- fracturelabs/spring4shell_victim2★ · 2022-04-07
- fransvanbuul/CVE-2022-22965-susceptibility0★ · 2022-04-09
- gokul-ramesh/Spring4Shell-PoC-exploit1★ · 2023-03-17
- govindarajulumedini/docker-poc0★ · 2022-12-28
- gpiechnik2/nmap-spring4shell8★ · 2022-04-08
- guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-229650★ · 2024-11-06
- helsecert/CVE-2022-229651★ · 2022-04-04
- iloveflag/Fast-CVE-2022-229654★ · 2022-11-08
- irgoncalves/irule-cve-2022-229652★ · 2022-04-06
- itsecurityco/CVE-2022-2296516★ · 2022-04-03
- jakabakos/CVE-2022-22965-Spring4Shell2★ · 2023-06-21
- jakabakos/spring4shell2★ · 2023-06-21
- khidottrivi/CVE-2022-229654★ · 2022-04-27
- kongjiexi/reznok-Spring4Shell-POC0★ · 2022-04-04
- lamyongxian/crmmvc0★ · 2022-04-29
- lamyongxian/cs5439-spring4shell1★ · 2023-11-14
- lcarea/CVE-2022-229651★ · 2022-04-01
- lcarea/PocSuite_POC0★ · 2022-04-01
- light-Life/CVE-2022-22965-GUItools17★ · 2022-04-02
- likewhite/CVE-2022-229653★ · 2023-01-31
- lucasferreiram3/Spring4Shell-POC0★ · 2024-06-14
- luoqianlin/CVE-2022-229650★ · 2022-04-05
- magicming200/ChatGPT-Function-Call-Red-Team-Tool5★ · 2023-11-09
- mamba-2021/EXP-POC26★ · 2023-01-11
- mariomamo/CVE-2022-229655★ · 2022-04-28
- marypyleung/SpringScan0★ · 2025-06-17
- me2nuk/CVE-2022-2296514★ · 2022-04-04
- mwojterski/cve-2022-229650★ · 2022-04-02
- netcode/Spring4shell-CVE-2022-22965-POC3★ · 2022-04-04
- nu0l/CVE-2022-229654★ · 2022-04-08
- osungjinwoo/CVE-2022-229650★ · 2025-08-01
- p1ckzi/CVE-2022-2296523★ · 2022-06-30
- rajasoun/spring4shell-tomcat1★ · 2023-05-23
- reznok/Spring4Shell-POC325★ · 2022-08-04
- ribeirux/spring4shell2★ · 2022-06-29
- robiul-awal/CVE-2022-229653★ · 2023-12-26
- rwincey/spring4shell-CVE-2022-229652★ · 2022-04-01
- snicoll-scratches/spring-boot-cve-2022-229650★ · 2022-04-13
- sohamsharma966/Spring4Shell-CVE-2022-229650★ · 2023-09-02
- sunnyvale-it/CVE-2022-22965-PoC7★ · 2023-04-27
- t3amj3ff/Spring4ShellPoC0★ · 2022-04-08
- talentsec/SpringShell1★ · 2022-04-01
- tangxiaofeng7/CVE-2022-22965-Spring-CachedintrospectionResults-Rce39★ · 2022-04-01
- tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce39★ · 2022-04-01
- te5t321/Spring4Shell-CVE-2022-22965.py0★ · 2022-04-10
- twseptian/cve-2022-229652★ · 2022-04-04
- viniciuspereiras/CVE-2022-22965-poc13★ · 2023-11-29
- wikiZ/springboot_CVE-2022-229656★ · 2022-04-07
- wjl110/CVE-2022-22965_Spring_Core_RCE16★ · 2022-04-02
- xnderLAN/CVE-2022-229650★ · 2022-04-05
- xsxtw/SpringFramework_CVE-2022-22965_RCE0★ · 2024-05-01
- zangcc/CVE-2022-22965-rexbb102★ · 2023-11-14
- zer0yu/CVE-2022-2296512★ · 2022-04-07
- 0xBlackash/CVE-2022-22965
- Kuri119/CVE-2022-22965-Spring4Shell
- PrinceH4k/Spring4Shell-POC
- march0n/PoC-CVE-2022-22965-Spring4Shell
- nhattanhh/CVE-2022-22965
- DataDog/security-labs-pocs
- Fhwang0926/seo-labs
- JishiTeam-J1wa/FuckSpringScan
- RBKD-SEC/POC
- RaienRaies/spring4shell-poc
- SimoesCTT/CTT-ProxyLogon-RCE-v1.0---Convergent-Time-Theory-Enhanced-Microsoft-Exchange-Ex…
- ckiellandpanw/brokenbank
- foiscs/security_project4
- kasia-kittel/Spring4ShellExample
- light0921/webscanner
- mannmain/kb-python-dz-10-exploit
- onewinner/VulToolsKit