<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:07:56.310736+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01631</id>
    <title>bdu:2022-01631</title>
    <updated>2026-10-02T15:07:56.519173+00:00</updated>
    <content>bdu:2022-01631</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-297</id>
    <title>certfr-2022-avi-297 — Une vulnérabilité a été découverte dans VMware Spring. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
    <updated>2026-10-02T15:07:56.519229+00:00</updated>
    <content>certfr-2022-avi-297</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-297"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-java-spring-rce-zx9guc67</id>
    <title>cisco-sa-java-spring-rce-Zx9GUc67 — Vulnerability in Spring Framework Affecting Cisco Products: March 2022</title>
    <updated>2026-10-02T15:07:56.519268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released:

    CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+

For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report ["https://tanzu.vmware.com/security/cve-2022-22965"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-java-spring-rce-zx9guc67"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255853</id>
    <title>EUVD-2026-255853</title>
    <updated>2026-10-02T15:07:56.519300+00:00</updated>
    <content>EUVD-2026-255853</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22965</id>
    <title>fkie_cve-2022-22965</title>
    <updated>2026-10-02T15:07:56.519313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-22965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36p3-wjmg-h94x</id>
    <title>GHSA-36p3-wjmg-h94x — Remote Code Execution in Spring Framework</title>
    <updated>2026-10-02T15:07:56.519336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.springframework:spring-beans, Maven: org.springframework:spring-webmvc, Maven: org.springframework.boot:spring-boot-starter-web, Maven: org.springframework:spring-webflux, Maven: org.springframework.boot:spring-boot-starter-webflux</p>
<p>Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as `Spring4Shell`.</p>
<p>## Impact</p>
<p>A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.</p>
<p>These are the prerequisites for the exploit:
- JDK 9 or higher
- Apache Tomcat as the Servlet container
- Packaged as WAR
- `spring-webmvc` or `spring-webflux` dependency</p>
<p>## Patches</p>
<p>- Spring Framework [5.3.18](https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18) and [5.2.20](https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE)
- Spring Boot [2.6.6](https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6) and [2.5.12](https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12)</p>
<p>## Workarounds</p>
<p>For those who are unable to upgrade, leaked reports recommend setting `disallowedFields` on `WebDataBinder` through an `@ControllerAdvice`. This works generally, but as a centrally applied workaround fix, may leave some loopholes, in particular if a controller sets `disallowedFields` locally through its own `@InitBinder` method, which overrides the global…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36p3-wjmg-h94x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-22965</id>
    <title>gsd-2022-22965</title>
    <updated>2026-10-02T15:07:56.519388+00:00</updated>
    <content>gsd-2022-22965</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-22965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-286-05</id>
    <title>ICSA-22-286-05 — Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service</title>
    <updated>2026-10-02T15:07:56.519401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability exists in the Spring Framework component included in the Prognostic Model Executor service of the affected product. An attacker could exploit this vulnerability by sending a specially crafted data or configuration to the application either directly or via integrated applications, causing the Prognostic Model Executor service to fail.CVE-2022-22950 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). A vulnerability in the Spring Framework component included in the Prognostic Model Executor service could allow an attacker to inject arbitrary code for remote code execution.CVE-2022-22965 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-286-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1306</id>
    <title>RHSA-2022:1306 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1-1 security update</title>
    <updated>2026-10-02T15:07:56.519423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>spring-framework: RCE via Data Binding on JDK 9+</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22965</id>
    <title>UBUNTU-CVE-2022-22965</title>
    <updated>2026-10-02T15:07:56.519439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java</p>
<p>A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0033</id>
    <title>WID-SEC-W-2022-0033 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode</title>
    <updated>2026-10-02T15:07:56.519465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0033"/>
  </entry>
</feed>
