<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:12:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-01631</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01631</link>
      <description>bdu:2022-01631</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01631</guid>
    </item>
    <item>
      <title>certfr-2022-avi-297 — Une vulnérabilité a été découverte dans VMware Spring. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-297</link>
      <description>certfr-2022-avi-297</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-297</guid>
    </item>
    <item>
      <title>cisco-sa-java-spring-rce-Zx9GUc67 — Vulnerability in Spring Framework Affecting Cisco Products: March 2022</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-java-spring-rce-zx9guc67</link>
      <description>&lt;p&gt;On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released:&#13;
&#13;
    CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+&#13;
&#13;
For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report [&amp;#34;https://tanzu.vmware.com/security/cve-2022-22965&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released:&#13;
&#13;
    CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+&#13;
&#13;
For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report [&amp;#34;https://tanzu.vmware.com/security/cve-2022-22965&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-java-spring-rce-zx9guc67</guid>
    </item>
    <item>
      <title>EUVD-2026-255853</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255853</link>
      <description>EUVD-2026-255853</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255853</guid>
    </item>
    <item>
      <title>fkie_cve-2022-22965</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-22965</link>
      <description>&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-22965</guid>
    </item>
    <item>
      <title>GHSA-36p3-wjmg-h94x — Remote Code Execution in Spring Framework</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-36p3-wjmg-h94x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-beans, Maven: org.springframework:spring-webmvc, Maven: org.springframework.boot:spring-boot-starter-web, Maven: org.springframework:spring-webflux, Maven: org.springframework.boot:spring-boot-starter-webflux&lt;/p&gt;
&lt;p&gt;Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as `Spring4Shell`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;
&lt;p&gt;These are the prerequisites for the exploit:
- JDK 9 or higher
- Apache Tomcat as the Servlet container
- Packaged as WAR
- `spring-webmvc` or `spring-webflux` dependency&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- Spring Framework [5.3.18](https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18) and [5.2.20](https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE)
- Spring Boot [2.6.6](https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6) and [2.5.12](https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12)&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;For those who are unable to upgrade, leaked reports recommend setting `disallowedFields` on `WebDataBinder` through an `@ControllerAdvice`. This works generally, but as a centrally applied workaround fix, may leave some loopholes, in particular if a controller sets `disallowedFields` locally through its own `@InitBinder` method, which overrides the global…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.springframework:spring-beans, Maven: org.springframework:spring-webmvc, Maven: org.springframework.boot:spring-boot-starter-web, Maven: org.springframework:spring-webflux, Maven: org.springframework.boot:spring-boot-starter-webflux&lt;/p&gt;
&lt;p&gt;Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as `Spring4Shell`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;
&lt;p&gt;These are the prerequisites for the exploit:
- JDK 9 or higher
- Apache Tomcat as the Servlet container
- Packaged as WAR
- `spring-webmvc` or `spring-webflux` dependency&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- Spring Framework [5.3.18](https://github.com/spring-projects/spring-framework/releases/tag/v5.3.18) and [5.2.20](https://github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE)
- Spring Boot [2.6.6](https://github.com/spring-projects/spring-boot/releases/tag/v2.6.6) and [2.5.12](https://github.com/spring-projects/spring-boot/releases/tag/v2.5.12)&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;For those who are unable to upgrade, leaked reports recommend setting `disallowedFields` on `WebDataBinder` through an `@ControllerAdvice`. This works generally, but as a centrally applied workaround fix, may leave some loopholes, in particular if a controller sets `disallowedFields` locally through its own `@InitBinder` method, which overrides the global…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-36p3-wjmg-h94x</guid>
    </item>
    <item>
      <title>gsd-2022-22965</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-22965</link>
      <description>gsd-2022-22965</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-22965</guid>
    </item>
    <item>
      <title>ICSA-22-286-05 — Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-286-05</link>
      <description>&lt;p&gt;A vulnerability exists in the Spring Framework component included in the Prognostic Model Executor service of the affected product. An attacker could exploit this vulnerability by sending a specially crafted data or configuration to the application either directly or via integrated applications, causing the Prognostic Model Executor service to fail.CVE-2022-22950 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). A vulnerability in the Spring Framework component included in the Prognostic Model Executor service could allow an attacker to inject arbitrary code for remote code execution.CVE-2022-22965 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in the Spring Framework component included in the Prognostic Model Executor service of the affected product. An attacker could exploit this vulnerability by sending a specially crafted data or configuration to the application either directly or via integrated applications, causing the Prognostic Model Executor service to fail.CVE-2022-22950 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). A vulnerability in the Spring Framework component included in the Prognostic Model Executor service could allow an attacker to inject arbitrary code for remote code execution.CVE-2022-22965 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-286-05</guid>
    </item>
    <item>
      <title>RHSA-2022:1306 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1-1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1306</link>
      <description>&lt;p&gt;spring-framework: RCE via Data Binding on JDK 9+&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;spring-framework: RCE via Data Binding on JDK 9+&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1306</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-22965</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22965</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java&lt;/p&gt;
&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: libspring-java, Ubuntu:Pro:20.04:LTS: libspring-java, Ubuntu:Pro:22.04:LTS: libspring-java, Ubuntu:Pro:24.04:LTS: libspring-java, Ubuntu:25.10: libspring-java&lt;/p&gt;
&lt;p&gt;A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-22965</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0033 — VMware Tanzu Spring Framework: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0033</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VMware Tanzu Spring Framework ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0033</guid>
    </item>
  </channel>
</rss>
