← Vulnerability feed

Vulnerability record · CVE-2016-4977 · published 25 May 2017

CVE-2016-4977: Spring Security OAuth whitelabel views SpEL injection enables RCE

Pivotal · Spring Security Oauth

Spring Security OAuth versions 2.0.0-2.0.9 and 1.0.0-1.0.5 execute the response_type parameter as Spring Expression Language (SpEL) when processing authorization requests through the whitelabel views. Because the value is evaluated as an expression rather than treated as data, an attacker can inject SpEL that runs arbitrary code on the server. This is a high-severity remote code execution flaw in a widely used authorization component.

8.8 CVSS 3.0 High EPSS 79% · top 0.4% CWE-19 · CWE-19
8.8CVSS 3.0 base score, v2 6.5
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote code execution with a CVSS of 8.8 and an EPSS above the 99th percentile, though exploitation requires a low-privilege authenticated position.

What it is

Spring Security OAuth versions 2.0.0-2.0.9 and 1.0.0-1.0.5 execute the response_type parameter as Spring Expression Language (SpEL) when processing authorization requests through the whitelabel views. Because the value is evaluated as an expression rather than treated as data, an attacker can inject SpEL that runs arbitrary code on the server. This is a high-severity remote code execution flaw in a widely used authorization component.

Impact

An attacker who can reach the OAuth authorization endpoint gains remote code execution with the privileges of the application server, allowing full compromise of the host and any data or credentials it can reach.

Attack surface

Reached over the network via the OAuth authorization request, specifically the response_type parameter handled by the whitelabel views. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates a low-privilege authenticated attacker is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.79176 probability, 99.579th percentile), indicating substantial observed or expected exploitation activity.

What to do

  • Upgrade Spring Security OAuth to a version outside the affected ranges (2.0.0-2.0.9 and 1.0.0-1.0.5) as directed by the vendor advisory.
  • If immediate upgrade is not possible, disable or replace the whitelabel authorization views so the response_type value is not evaluated as SpEL.
  • Restrict network access to OAuth authorization endpoints to trusted clients and networks.
  • Review application logs and server behavior for unexpected expression evaluation or command execution around authorization requests.
  • Monitor the vendor advisory and apply any follow-up patches or configuration guidance.

Detection

  • Inspect HTTP requests to OAuth authorization endpoints for response_type values containing SpEL syntax such as T(), #{}, or Runtime/ProcessBuilder references.
  • Alert on anomalous child processes or command execution spawned by the Java application server hosting Spring Security OAuth.
  • Correlate authorization endpoint access with subsequent outbound connections or file writes from the application host.
  • Review application and WAF logs for encoded or obfuscated response_type parameters that deviate from expected OAuth grant type values.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2022-22969Pivotal spring security oauth vulnerability<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) a…EPSS 1.3%8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2021-30952Apple WebKit integer overflow allows code execution via crafted web contentAn integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15…KEVEPSS 7.0%analysed7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.2%analysed7.8CVE-2018-14634Linux kernel create_elf_tables() integer overflow privilege escalationAn integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise p…KEVEPSS 15%analysed7.8CVE-2025-24985Windows Fast FAT Driver integer overflow enables local code executionThe Windows Fast FAT driver contains an integer overflow that leads to a heap-based buffer overflow. A crafted FAT filesystem operation can corrupt h…KEVEPSS 3.8%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed8.4CVE-2022-0185Linux Kernel Filesystem Context Heap Buffer OverflowThe legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a…KEVEPSS 25%analysed

Source: NIST National Vulnerability Database (record CVE-2016-4977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.