Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild

Spring Framework RCE Vulnerability CVE-2022-22965 Exploited in the Wild

First seen 17 Jun 2026, 11:40 UTC Rapid7spring.iotanzu.vmware.comendoflife.date 80% similarity 74.0

Article Content

Browse articles
ThreatCluster

On March 30, 2022, a zero-day remote code execution vulnerability in the Spring Framework, dubbed 'Spring4Shell' and assigned CVE-2022-22965, was disclosed. This vulnerability affects Spring MVC and Spring WebFlux applications running on JDK 9+ and requires deployment on Tomcat as a WAR file. Multiple security vendors, including Rapid7, confirmed in-the-wild exploitation attempts, although activity appears limited to a small number of actors. The CVSS score for this vulnerability is 9.8, indicating critical severity. Spring released a fix on April 1, 2022, and users are urged to upgrade to Spring Framework versions 5.3.18 or 5.2.20 or greater. Workarounds are available for those unable to upgrade immediately. The vulnerability was reported by researchers from AntGroup FG and Praetorian.

Key Points: • CVE-2022-22965 is a critical RCE vulnerability in Spring Framework with a CVSS score of 9.8. • Exploitation requires applications to run on Tomcat as a WAR deployment; Spring Boot executable jars are not affected. • Users are advised to upgrade to Spring Framework 5.3.18 or 5.2.20+ to mitigate the vulnerability.

ThreatCluster AI How this analysis works

Timeline

2022-03-30
First public PoC released
A researcher published a technical writeup and PoC exploit code for CVE-2022-22965, which was later deleted.
Rapid7
2022-03-31
Spring confirms vulnerability
Spring Framework acknowledged the RCE vulnerability and confirmed it as a ClassLoader manipulation issue.
spring.io
2022-04-01
CVE-2022-22965 published
CVE-2022-22965 was officially published, detailing the RCE vulnerability in Spring Framework.
tanzu.vmware.com
2022-04-04
CVE added to CISA KEV
CISA added CVE-2022-22965 to its Known Exploited Vulnerabilities catalog due to active exploitation.
tanzu.vmware.com

Community

Browse all →