What happened
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Affected versions
Spring Framework: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · BobTheShoplifter/Spring4Shell-POCSpring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965★ 376BobTheShoplifter2022-03-30CandidatePoC-in-GitHub · Mr-xn/spring-core-rceCVE-2022-22965 : about spring core rce★ 50Mr-xn2022-03-30CandidatePoC-in-GitHub · TheGejr/SpringShellSpring4Shell - Spring Core RCE - CVE-2022-22965★ 131TheGejr2022-03-30CandidatePoC-in-GitHub · reznok/Spring4Shell-POCDockerized Spring4Shell (CVE-2022-22965) PoC application and exploit★ 325reznok2022-03-31CandidatePoC-in-GitHub · Bouquets-ai/CVE-2022-22965-GUItoolsspring-core单个图形化利用工具,CVE-2022-22965及修复方案已出★ 17Bouquets-ai2022-03-31CandidatePoC-in-GitHub · DDuarte/springshell-rce-pocCVE-2022-22965 - CVE-2010-1622 redux★ 19DDuarte2022-03-31CandidatePoC-in-GitHub · k3rwin/spring-core-rcespring框架RCE漏洞 CVE-2022-22965★ 27k3rwin2022-03-31CandidatePoC-in-GitHub · liangyueliangyue/spring-core-rcespringFramework_CVE-2022-22965_RCE简单利用★ 26liangyueliangyue2022-03-31CandidatePoC-in-GitHub · Kirill89/CVE-2022-22965-PoC★ 32Kirill892022-03-31CandidatePoC-in-GitHub · FourCoreLabs/spring4shell-exploit-pocExploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.★ 44FourCoreLabs2022-03-31CandidatePoC-in-GitHub · alt3kx/CVE-2022-22965_PoCSpring Framework RCE (Quick pentest notes)★ 17alt3kx2022-03-31CandidatePoC-in-GitHub · GuayoyoCyber/CVE-2022-22965Vulnerabilidad RCE en Spring Framework vía Data Binding on JDK 9+ (CVE-2022-22965 aka "Spring4Shell")★ 6GuayoyoCyber2022-03-31CandidatePoC-in-GitHub · colincowie/Safer_PoC_CVE-2022-22965A Safer PoC for CVE-2022-22965 (Spring4Shell)★ 44colincowie2022-03-31CandidatePoC-in-GitHub · rwincey/spring4shell-CVE-2022-22965★ 2rwincey2022-03-31CandidatePoC-in-GitHub · viniciuspereiras/CVE-2022-22965-pocCVE-2022-22965 poc including reverse-shell support★ 13viniciuspereiras2022-03-31CandidatePoC-in-GitHub · mebibite/springhoundCreated after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.★ 0mebibite2022-04-01CandidatePoC-in-GitHub · likewhite/CVE-2022-22965CVE-2022-22965 EXP★ 3likewhite2022-04-01CandidatePoC-in-GitHub · SecNN/SpringFramework_CVE-2022-22965_RCESpringFramework 远程代码执行漏洞CVE-2022-22965★ 72SecNN2022-04-01CandidatePoC-in-GitHub · snicoll-scratches/spring-boot-cve-2022-22965Showcase of overridding the Spring Framework version in older Spring Boot versions★ 0snicoll-scratches2022-04-01CandidatePoC-in-GitHub · nu0l/CVE-2022-22965Spring-0day/CVE-2022-22965★ 4nu0l2022-04-01CandidatePoC-in-GitHub · tangxiaofeng7/CVE-2022-22965-Spring-Core-Rce批量无损检测CVE-2022-22965★ 39tangxiaofeng72022-04-01CandidatePoC-in-GitHub · helsecert/CVE-2022-22965★ 1helsecert2022-04-01CandidatePoC-in-GitHub · lcarea/CVE-2022-22965★ 1lcarea2022-04-01CandidatePoC-in-GitHub · Joe1sn/CVE-2022-22965CVE-2022-22965 Environment★ 1Joe1sn2022-04-01CandidatePoC-in-GitHub · zer0yu/CVE-2022-22965Spring4Shell (CVE-2022-22965)★ 12zer0yu2022-04-01CandidatePoC-in-GitHub · me2nuk/CVE-2022-22965Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965★ 14me2nuk2022-04-01CandidatePoC-in-GitHub · wshon/spring-framework-rceCVE-2022-22965★ 4wshon2022-04-01CandidatePoC-in-GitHub · Wrin9/CVE-2022-22965CVE-2022-22965 POC★ 7Wrin92022-04-02CandidatePoC-in-GitHub · wjl110/CVE-2022-22965_Spring_Core_RCECVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用★ 16wjl1102022-04-02CandidatePoC-in-GitHub · mwojterski/cve-2022-22965★ 0mwojterski2022-04-02CandidatePoC-in-GitHub · gpiechnik2/nmap-spring4shellNmap Spring4Shell NSE script for Spring Boot RCE (CVE-2022-22965)★ 8gpiechnik22022-04-03CandidatePoC-in-GitHub · itsecurityco/CVE-2022-22965Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5★ 16itsecurityco2022-04-03CandidatePoC-in-GitHub · daniel0x00/Invoke-CVE-2022-22965-SafeCheckPowerShell port of CVE-2022-22965 vulnerability check by colincowie.★ 1daniel0x002022-04-04CandidatePoC-in-GitHub · fracturelabs/spring4shell_victimIntentionally vulnerable Spring app to test CVE-2022-22965★ 2fracturelabs2022-04-04CandidatePoC-in-GitHub · sunnyvale-it/CVE-2022-22965-PoCCVE-2022-22965 (Spring4Shell) Proof of Concept★ 7sunnyvale-it2022-04-04CandidatePoC-in-GitHub · twseptian/cve-2022-22965Spring4Shell - CVE-2022-22965★ 2twseptian2022-04-04CandidatePoC-in-GitHub · netcode/Spring4shell-CVE-2022-22965-POCAnother spring4shell (Spring core RCE) POC★ 3netcode2022-04-04CandidatePoC-in-GitHub · fracturelabs/go-scan-springVulnerability scanner for Spring4Shell (CVE-2022-22965)★ 12fracturelabs2022-04-04CandidatePoC-in-GitHub · Snip3R69/spring-shell-vulnSpring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this vulnerability can be tracked as CVE-2022-22965.★ 1Snip3R692022-04-05CandidatePoC-in-GitHub · 0xr1l3s/CVE-2022-22965Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30★ 00xr1l3s2022-04-05CandidatePoC-in-GitHub · luoqianlin/CVE-2022-22965Spring Framework RCE Exploit★ 0luoqianlin2022-04-05CandidatePoC-in-GitHub · 0xrobiul/CVE-2022-22965Exploit Of Spring4Shell!★ 30xrobiul2022-04-05CandidatePoC-in-GitHub · LudovicPatho/CVE-2022-22965_Spring4ShellA Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.★ 2LudovicPatho2022-04-05CandidatePoC-in-GitHub · irgoncalves/irule-cve-2022-22965★ 2irgoncalves2022-04-06CandidatePoC-in-GitHub · datawiza-inc/spring-rec-demoThe demo code showing the recent Spring4Shell RCE (CVE-2022-22965)★ 2datawiza-inc2022-04-06CandidatePoC-in-GitHub · alt3kx/CVE-2022-22965Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)★ 100alt3kx2022-04-07CandidatePoC-in-GitHub · wikiZ/springboot_CVE-2022-22965CVE-2022-22965 pocsuite3 POC★ 6wikiZ2022-04-07CandidatePoC-in-GitHub · 4nth0ny1130/spring4shell_behinderCVE-2022-22965写入冰蝎webshell脚本★ 624nth0ny11302022-04-07CandidatePoC-in-GitHub · t3amj3ff/Spring4ShellPoCSpring4Shell PoC (CVE-2022-22965)★ 0t3amj3ff2022-04-07CandidatePoC-in-GitHub · CalumHutton/CVE-2022-22965-PoC_Payara★ 3CalumHutton2022-04-07CandidatePoC-in-GitHub · fransvanbuul/CVE-2022-22965-susceptibility★ 0fransvanbuul2022-04-09CandidatePoC-in-GitHub · te5t321/Spring4Shell-CVE-2022-22965.pyScript to check for Spring4Shell vulnerability★ 0te5t3212022-04-11CandidatePoC-in-GitHub · Loneyers/Spring4ShellSpring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin★ 4Loneyers2022-04-11CandidatePoC-in-GitHub · p1ckzi/CVE-2022-22965spring4shell | CVE-2022-22965★ 23p1ckzi2022-04-12CandidatePoC-in-GitHub · Omaraitbenhaddi/-Spring4Shell-CVE-2022-22965-exploitation script tryhackme★ 0Omaraitbenhaddi2022-04-13CandidatePoC-in-GitHub · c4mx/CVE-2022-22965_PoC★ 1c4mx2022-04-21CandidatePoC-in-GitHub · mariomamo/CVE-2022-22965★ 5mariomamo2022-04-23CandidatePoC-in-GitHub · khidottrivi/CVE-2022-22965★ 4khidottrivi2022-04-27CandidatePoC-in-GitHub · Enokiy/spring-RCE-CVE-2022-22965★ 0Enokiy2022-04-29CandidatePoC-in-GitHub · cxzero/CVE-2022-22965-spring4shellCVE-2022-22965 Spring4Shell research & PoC★ 1cxzero2022-05-19CandidatePoC-in-GitHub · tpt11fb/SpringVulScanburpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977★ 155tpt11fb2022-06-19CandidatePoC-in-GitHub · D1mang/Spring4Shell-CVE-2022-22965EXP for Spring4Shell(CVE-2022-22965)★ 2D1mang2022-07-05CandidatePoC-in-GitHub · iloveflag/Fast-CVE-2022-22965CVE-2022-22965图形化检测工具★ 4iloveflag2022-11-08CandidatePoC-in-GitHub · clemoregan/SSE4-CVE-2022-22965CVE-2022-22965 proof of concept★ 1clemoregan2022-11-28CandidatePoC-in-GitHub · devengpk/CVE-2022-22965★ 0devengpk2022-12-12CandidatePoC-in-GitHub · zangcc/CVE-2022-22965-rexbbCVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。★ 102zangcc2022-12-28CandidatePoC-in-GitHub · ajith737/Spring4Shell-CVE-2022-22965-POCUser friendly Spring4Shell POC★ 0ajith7372023-01-03CandidatePoC-in-GitHub · c33dd/CVE-2022-22965🚀 Exploit for Spring core RCE in C [ wip ]★ 0c33dd2023-03-02CandidatePoC-in-GitHub · gokul-ramesh/Spring4Shell-PoC-exploitDemonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)★ 1gokul-ramesh2023-03-12CandidatePoC-in-GitHub · bL34cHig0/Telstra-Cybersecurity-Virtual-Experience-A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability★ 2bL34cHig02023-05-31CandidatePoC-in-GitHub · BKLockly/CVE-2022-22965Poc&Exp,支持批量扫描,反弹shell★ 3BKLockly2023-06-03CandidatePoC-in-GitHub · dbgee/Spring4ShellSpring rce environment for CVE-2022-22965★ 0dbgee2023-06-07CandidatePoC-in-GitHub · jakabakos/CVE-2022-22965-Spring4ShellPoC and exploit for CVE-2022-22965 Spring4Shell★ 2jakabakos2023-06-20CandidatePoC-in-GitHub · sohamsharma966/Spring4Shell-CVE-2022-22965★ 0sohamsharma9662023-09-02CandidatePoC-in-GitHub · LucasPDiniz/CVE-2022-22965Spring4Shell Vulnerability RCE - CVE-2022-22965★ 0LucasPDiniz2023-11-12CandidatePoC-in-GitHub · ESSAFAR/Firewall-RulesFirewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell★ 0ESSAFAR2023-11-21CandidatePoC-in-GitHub · xsxtw/SpringFramework_CVE-2022-22965_RCE★ 0xsxtw2024-05-01CandidatePoC-in-GitHub · Aur3ns/Block-Spring4ShellPOC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit★ 0Aur3ns2024-11-02CandidatePoC-in-GitHub · guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965★ 0guigui2372024-11-05CandidatePoC-in-GitHub · jashan-lefty/Spring4ShellIn this challenge, I analyzed the Spring4Shell (CVE-2022-22965) vulnerability, investigated security bypasses, and wrote an Incident Postmortem Report detailing the detection, impact, and resolution of the attack. I also implemented a firewall rule in Python to block malicious requests and prevent future exploitation.★ 0jashan-lefty2025-02-03CandidatePoC-in-GitHub · brunoh6/web-threat-mitigationHands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell (CVE-2022-22965). Local Docker-based setup.★ 0brunoh62025-06-11CandidatePoC-in-GitHub · osungjinwoo/CVE-2022-22965Spring4Shell (POC)★ 0osungjinwoo2025-08-01CandidatePoC-in-GitHub · Nosie12/fire-wall-serverPython-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying malicious payload patterns using a custom firewall_server.py and tests them with test_requests.py.★ 0Nosie122025-08-01CandidatePoC-in-GitHub · salo-404/firewall🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August 2025 through Forage. It focuses on detecting, analyzing, and mitigating a simulated real-world cyberattack involving the Spring4Shell (CVE-2022-22965) vulnerability★ 1salo-4042025-08-06CandidatePoC-in-GitHub · shoucheng3/spring-projects__spring-framework_CVE-2022-22965_5-2-19-RELEASE★ 0shoucheng32025-08-20CandidatePoC-in-GitHub · NickoPS87/Spring4Shell-Python-Firewall-POCProof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking malicious request bodies.★ 0NickoPS872025-10-19CandidatePoC-in-GitHub · xenosf/CS4239-Spring4Shell-POCCVE-2022-22965 proof of concept for CS4239 report★ 0xenosf2025-11-14CandidatePoC-in-GitHub · mylo-2001/GhostStrikeFully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework★ 1mylo-20012025-11-20CandidatePoC-in-GitHub · nhattanhh/CVE-2022-22965Spring4Shell★ 0nhattanhh2025-12-22CandidatePoC-in-GitHub · Shakur1314/CVE-2022-22965-Spring4Shell-Security-Operations-AnalysisA comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the Spring4Shell vulnerability (CVE-2022-22965).★ 0Shakur13142026-01-14CandidatePoC-in-GitHub · suyash-R-K/dfir-malware-investigationSpring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.★ 0suyash-R-K2026-01-20CandidatePoC-in-GitHub · aditidutta696-dev/Spring4Shell-CVE-2022-22965-Exploitation-Attempt★ 0aditidutta696-dev2026-02-03CandidatePoC-in-GitHub · 0xBlackash/CVE-2022-22965CVE-2022-22965★ 00xBlackash2026-03-01CandidatePoC-in-GitHub · felisha-elmer/Sandbox-Challenge-Spring4Shell-CVE-2022-22965-★ 0felisha-elmer2026-05-22CandidatePoC-in-GitHub · YUTING-HUANG0/Spring4Shell-CTFSpring4Shell (CVE-2022-22965) 漏洞環境搭建與 CTF 題目★ 0YUTING-HUANG02026-05-27CandidatePoC-in-GitHub · march0n/PoC-CVE-2022-22965-Spring4ShellDescription★ 0march0n2026-05-27CandidatePoC-in-GitHub · Kuri119/CVE-2022-22965-Spring4Shell★ 0Kuri1192026-06-30CandidatePoC-in-GitHub · meng-security/spring4shell-local-verification-labSpring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目★ 0meng-security2026-07-15CandidatePoC-in-GitHub · PrinceH4k/Spring4Shell-POCProof of Concept for exploiting the CVE-2022-22965 (Spring4Shell) vulnerability in an isolated environment, with Remote Code Execution (RCE) demonstrated.★ 0PrinceH4k2026-08-03CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.