critical
CVE-2022-22965
Spring4Shell RCE via data binding
- Severity
- critical
- Affected product
- Spring Framework
- Affected versions
- Spring Framework ≥ 5.3.0, < 5.3.18
- Fixed in
- Spring Framework 5.3.18
- Added to NewScan
- 2026-06-29
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Spring Framework from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →