⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2022-22965

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

SpringShell/Spring4Shell: RCE via data binding in Spring Framework — affects all apps on Spring MVC/WebFlux with JDK 9+. Exploited by Mirai botnets within hours of disclosure. Update Spring Framework to 5.3.18/5.2.20+. Verify JDK versions.

📋 Official Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. SpringShell.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →