CVE-2022-22965

ENISA EUVD: EUVD-2022-1283 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 11 articles Published: 2022-04-01

EPSS Score

Source: FIRST.org · 2026-05-23
94.46%
probability
This CVE has a 94.46% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
9.8
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 (legacy)

7.5
HIGH
Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

VulnerabilityLookup (CNA)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Affected Products

n/a
Spring Framework
Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions

Attack Intelligence

Exploits & PoC

BobTheShoplifter/Spring4Shell-POC

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

377 2022-11-09
reznok/Spring4Shell-POC

Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

324 2022-08-04
tpt11fb/SpringVulScan

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

154 2023-01-23
TheGejr/SpringShell

Spring4Shell - Spring Core RCE - CVE-2022-22965

131 2022-04-04
zangcc/CVE-2022-22965-rexbb

CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。

102 2023-11-14
alt3kx/CVE-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

101 2022-04-07
SecNN/SpringFramework_CVE-2022-22965_RCE

SpringFramework 远程代码执行漏洞CVE-2022-22965

72 2022-04-01
4nth0ny1130/spring4shell_behinder

CVE-2022-22965写入冰蝎webshell脚本

63 2022-05-10
Mr-xn/spring-core-rce

CVE-2022-22965 : about spring core rce

50 2022-04-01
FourCoreLabs/spring4shell-exploit-poc

Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.

44 2022-04-06
colincowie/Safer_PoC_CVE-2022-22965

A Safer PoC for CVE-2022-22965 (Spring4Shell)

44 2022-05-27
tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce

批量无损检测CVE-2022-22965

40 2022-04-01
k3rwin/spring-core-rce

spring框架RCE漏洞 CVE-2022-22965

28 2022-04-22
liangyueliangyue/spring-core-rce

springFramework_CVE-2022-22965_RCE简单利用

26 2022-04-07
p1ckzi/CVE-2022-22965

spring4shell | CVE-2022-22965

23 2022-06-30
DDuarte/springshell-rce-poc

CVE-2022-22965 - CVE-2010-1622 redux

19 2023-04-18
Bouquets-ai/CVE-2022-22965-GUItools

spring-core单个图形化利用工具,CVE-2022-22965及修复方案已出

17 2022-04-02
alt3kx/CVE-2022-22965_PoC

Spring Framework RCE (Quick pentest notes)

17 2022-04-07
wjl110/CVE-2022-22965_Spring_Core_RCE

CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用

16 2022-04-02
itsecurityco/CVE-2022-22965

Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5

16 2022-04-03
me2nuk/CVE-2022-22965

Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965

14 2022-04-04
viniciuspereiras/CVE-2022-22965-poc

CVE-2022-22965 poc including reverse-shell support

13 2023-11-29
zer0yu/CVE-2022-22965

Spring4Shell (CVE-2022-22965)

12 2022-04-07
fracturelabs/go-scan-spring

Vulnerability scanner for Spring4Shell (CVE-2022-22965)

12 2022-04-07
gpiechnik2/nmap-spring4shell

Nmap Spring4Shell NSE script for Spring Boot RCE (CVE-2022-22965)

8 2022-04-08
Wrin9/CVE-2022-22965

CVE-2022-22965 POC

7 2022-04-02
sunnyvale-it/CVE-2022-22965-PoC

CVE-2022-22965 (Spring4Shell) Proof of Concept

7 2023-04-27
GuayoyoCyber/CVE-2022-22965

Vulnerabilidad RCE en Spring Framework vía Data Binding on JDK 9+ (CVE-2022-22965 aka "Spring4Shell")

6 2022-04-19
wikiZ/springboot_CVE-2022-22965

CVE-2022-22965 pocsuite3 POC

6 2022-04-07
nu0l/CVE-2022-22965

Spring-0day/CVE-2022-22965

4 2022-04-08
4 2022-04-01
Loneyers/Spring4Shell

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

4 2022-04-11
iloveflag/Fast-CVE-2022-22965

CVE-2022-22965图形化检测工具

4 2022-11-08
likewhite/CVE-2022-22965

CVE-2022-22965 EXP

3 2023-01-31
netcode/Spring4shell-CVE-2022-22965-POC

Another spring4shell (Spring core RCE) POC

3 2022-04-04
0xrobiul/CVE-2022-22965

Exploit Of Spring4Shell!

3 2023-12-26
BKLockly/CVE-2022-22965

Poc&Exp,支持批量扫描,反弹shell

3 2023-06-04
fracturelabs/spring4shell_victim

Intentionally vulnerable Spring app to test CVE-2022-22965

2 2022-04-07
twseptian/cve-2022-22965

Spring4Shell - CVE-2022-22965

2 2022-04-04
LudovicPatho/CVE-2022-22965_Spring4Shell

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit r

2 2022-04-05
datawiza-inc/spring-rec-demo

The demo code showing the recent Spring4Shell RCE (CVE-2022-22965)

2 2022-04-07
D1mang/Spring4Shell-CVE-2022-22965

EXP for Spring4Shell(CVE-2022-22965)

2 2022-07-13
bL34cHig0/Telstra-Cybersecurity-Virtual-Experience-

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

2 2024-03-19
jakabakos/CVE-2022-22965-Spring4Shell

PoC and exploit for CVE-2022-22965 Spring4Shell

2 2023-06-21
Joe1sn/CVE-2022-22965

CVE-2022-22965 Environment

1 2022-04-02
daniel0x00/Invoke-CVE-2022-22965-SafeCheck

PowerShell port of CVE-2022-22965 vulnerability check by colincowie.

1 2022-04-04
Snip3R69/spring-shell-vuln

Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this

1 2022-04-05
cxzero/CVE-2022-22965-spring4shell

CVE-2022-22965 Spring4Shell research & PoC

1 2023-12-21
clemoregan/SSE4-CVE-2022-22965

CVE-2022-22965 proof of concept

1 2022-11-28
gokul-ramesh/Spring4Shell-PoC-exploit

Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)

1 2023-03-17
salo-404/firewall

🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August 2025

1 2025-09-23
mylo-2001/GhostStrike

Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework

1 2025-11-20
mebibite/springhound

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and systems,

0 2022-04-01
snicoll-scratches/spring-boot-cve-2022-22965

Showcase of overridding the Spring Framework version in older Spring Boot versions

0 2022-04-13
0xr1l3s/CVE-2022-22965

Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30

0 2022-04-05
luoqianlin/CVE-2022-22965

Spring Framework RCE Exploit

0 2022-04-05
t3amj3ff/Spring4ShellPoC

Spring4Shell PoC (CVE-2022-22965)

0 2022-04-08
te5t321/Spring4Shell-CVE-2022-22965.py

Script to check for Spring4Shell vulnerability

0 2022-04-10
0 2022-04-13
ajith737/Spring4Shell-CVE-2022-22965-POC

User friendly Spring4Shell POC

0 2023-01-03
c33dd/CVE-2022-22965

🚀 Exploit for Spring core RCE in C [ wip ]

0 2023-02-28
dbgee/Spring4Shell

Spring rce environment for CVE-2022-22965

0 2023-06-08
LucasPDiniz/CVE-2022-22965

Spring4Shell Vulnerability RCE - CVE-2022-22965

0 2024-06-30
ESSAFAR/Firewall-Rules

Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell

0 2023-11-21
Aur3ns/Block-Spring4Shell

POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit

0 2024-12-15
jashan-lefty/Spring4Shell

In this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report

0 2025-02-03
brunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell (

0 2025-06-11
osungjinwoo/CVE-2022-22965

Spring4Shell (POC)

0 2025-08-01
Nosie12/fire-wall-server

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying

0 2025-08-01
NickoPS87/Spring4Shell-Python-Firewall-POC

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking mal

0 2025-10-19
xenosf/CS4239-Spring4Shell-POC

CVE-2022-22965 proof of concept for CS4239 report

0 2025-11-14
0 2025-12-22
Shakur1314/CVE-2022-22965-Spring4Shell-Security-Operations-Analysis

A comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the

0 2026-03-04
suyash-R-K/dfir-malware-investigation

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

0 2026-02-01
0 2026-03-05
95 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 94.46%
CVSS v3.1 9.8
Mentions 11
Last Seen May 08, 2025

CNA Information

CNA Assigner
vmware

Analyst Note

CVE-2022-22965 (Spring4Shell) was exploited in the wild immediately after public disclosure on 2022-04-01, with exploitation documented before patches were widely available. The CRITICAL CVSS score, rapid real-world attacks, and CERT-EU security advisory confirm active exploitation coinciding with vulnerability disclosure, meeting zero-day criteria despite not being in Google Project Zero or CISA KEV.

Threat Actors 12

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Harvester
apt_group Information theft and espionage Unknown
Kinsing
apt_group 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
TeamTNT
apt_group 🇩🇪 DE
Rocke
apt_group 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 05, 2026
Published DateApr 01, 2022