⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2022-22963

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

Spring4Shell/SpringShell: SSTI via routing expression header in Spring Cloud Function. Affects Spring Cloud Function 3.1.6, 3.2.2 and older. Update to patched versions immediately. Exploited by Mirai botnet within hours of PoC release.

📋 Official Description

Spring Cloud Function Server-side template injection through the spring.cloud.function.routing-expression header leading to remote code execution.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →