VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Published 21 Aug 2026Updated 21 Aug 202632 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Affected versions

Spring Cloud: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 51577Spring Cloud 3.2.2 - Remote Command Execution (RCE)GatoGamer11552023-07-11VerifiedPoC-in-GitHub · hktalent/spring-spel-0day-pocspring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963★ 353hktalent2022-03-26CandidatePoC-in-GitHub · dinosn/CVE-2022-22963CVE-2022-22963 PoC★ 115dinosn2022-03-30CandidatePoC-in-GitHub · RanDengShiFu/CVE-2022-22963CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit★ 15RanDengShiFu2022-03-30CandidatePoC-in-GitHub · darryk10/CVE-2022-22963★ 34darryk102022-03-30CandidatePoC-in-GitHub · Kirill89/CVE-2022-22963-PoC★ 9Kirill892022-03-30CandidatePoC-in-GitHub · stevemats/Spring0DayCoreExploit{ Spring Core 0day CVE-2022-22963 }★ 3stevemats2022-03-30CandidatePoC-in-GitHub · puckiestyle/CVE-2022-22963★ 1puckiestyle2022-03-31CandidatePoC-in-GitHub · me2nuk/CVE-2022-22963Spring Cloud Function Vulnerable Application / CVE-2022-22963★ 19me2nuk2022-03-31CandidatePoC-in-GitHub · kh4sh3i/Spring-CVEThis includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".★ 14kh4sh3i2022-03-31CandidatePoC-in-GitHub · AayushmanThapaMagar/CVE-2022-22963POC for CVE-2022-22963★ 1AayushmanThapaMagar2022-04-01CandidatePoC-in-GitHub · twseptian/cve-2022-22963Spring Cloud Function SpEL - cve-2022-22963★ 2twseptian2022-04-03CandidatePoC-in-GitHub · SealPaPaPa/SpringCloudFunction-ResearchCVE-2022-22963 research★ 1SealPaPaPa2022-04-05CandidatePoC-in-GitHub · G01d3nW01f/CVE-2022-22963★ 0G01d3nW01f2022-04-11CandidatePoC-in-GitHub · k3rwin/spring-cloud-function-rceSpring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)★ 8k3rwin2022-04-14CandidatePoC-in-GitHub · iliass-dahman/CVE-2022-22963-POC★ 4iliass-dahman2023-01-15CandidatePoC-in-GitHub · charis3306/CVE-2022-22963spring cloud function 一键利用工具! by charis 博客https://charis3306.top/★ 8charis33062023-03-07CandidatePoC-in-GitHub · lemmyz4n3771/CVE-2022-22963-PoCCVE-2022-22963 RCE PoC in python★ 4lemmyz4n37712023-03-13CandidatePoC-in-GitHub · J0ey17/CVE-2022-22963_Reverse-Shell-ExploitCVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.★ 24J0ey172023-03-18CandidatePoC-in-GitHub · Mustafa1986/CVE-2022-22963★ 0Mustafa19862023-03-21CandidatePoC-in-GitHub · SourM1lk/CVE-2022-22963-ExploitRust-based exploit for the CVE-2022-22963 vulnerability★ 1SourM1lk2023-04-10CandidatePoC-in-GitHub · randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE★ 4randallbanner2023-04-17CandidatePoC-in-GitHub · gunzf0x/CVE-2022-22963Binaries for CVE-2022-22963★ 0gunzf0x2023-05-03CandidatePoC-in-GitHub · nikn0laty/RCE-in-Spring-Cloud-CVE-2022-22963Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function★ 0nikn0laty2023-05-25CandidatePoC-in-GitHub · BearClaw96/CVE-2022-22963-Poc-BearculesThis is a POC for CVE-2022-22963★ 0BearClaw962023-10-28CandidatePoC-in-GitHub · xmqaq/CVE-2022-22963CVE-2022-22963-poc★ 1xmqaq2023-12-28CandidatePoC-in-GitHub · jrbH4CK/CVE-2022-22963★ 0jrbH4CK2024-05-08CandidatePoC-in-GitHub · Shayz614/CVE-2022-22963CVE to CTF FP★ 0Shayz6142024-12-13CandidatePoC-in-GitHub · 808rsec/CVE-2022-22963Simple exploit★ 0808rsec2026-05-05CandidatePoC-in-GitHub · r4y-br/CVE-2022-22963Educational proof-of-concept automation for CVE-2022-22963, demonstrated in an authorized Hack The Box lab environment.★ 0r4y-br2026-08-22Candidate