Spring4Shell - Vulnerability

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 3, 2025
Last Seen
July 24, 2026

Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty).

Spring4Shell is a vulnerability tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 3, 2025; most recent activity July 24, 2026.

Overview

Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty). It has historically posed a major risk to Java-based web applications and driven widespread patching and mitigations. The provided article, however, discusses a critical React vulnerability (CVE-2025-55182) and Cloudflare's remediation, not Spring4Shell.

Related Threat Clusters

Recent Intelligence Reports

  • Zimbra's November 2025 security release — wiki.zimbra.com · July 24, 2026
  • Mitiga Blog News Jul 16, 2026 What is the Spring4Shell exploit? An overview of the Spring vulnerability mitiga.io Open source — www.mitiga.io · July 17, 2026
  • Spring4Shell Exposes Certain Spring Java Apps to Remote Code Execution — Mallory.Ai · July 17, 2026
  • Rapid7 Analysis: CVE-2022 — Rapid7 · June 17, 2026
  • Critical React Vulnerability CVE-2025-55182 Enables RCE; Cloudflare Deploys Fixes — Webpronews · December 3, 2025

Frequently asked questions

What is Spring4Shell?

Spring4Shell is a high-severity remote code execution vulnerability in the Spring Framework (notably CVE-2022-22965) that can allow unauthenticated attackers to execute arbitrary Java code on vulnerable servers when Spring MVC applications are misconfigured (e.g., running on Tomcat/Jetty).

Is Spring4Shell still active?

The most recent intelligence report mentioning Spring4Shell on ThreatCluster is dated July 24, 2026. Activity was first observed December 3, 2025, giving a tracked span from then to July 24, 2026.

What is Spring4Shell associated with?

Across ThreatCluster reporting, Spring4Shell most frequently co-occurs with Remote Code Execution, Sql Injection, Zero-day Exploit, CVE-2014-0224, CVE-2015-0204, among 12 tracked related entities.

What are the latest developments involving Spring4Shell?

The most significant recent cluster is “Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign” (59 articles · Updated July 23, 2026). Spring4Shell appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Spring4Shell?

Spring4Shell appears in 5 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown