Vulnerability record · CVE-2018-1270 · published 6 April 2018
CVE-2018-1270: Spring Framework STOMP over WebSocket broker remote code execution
Vmware · Spring Framework
Spring Framework versions 5.0 before 5.0.5 and 4.3 before 4.3.15 (plus older unsupported versions) allow applications to expose STOMP over WebSocket endpoints backed by a simple in-memory STOMP broker via spring-messaging. A crafted message to that broker can lead to remote code execution. Because the flaw is reachable over the network without credentials, it is a serious risk for any application exposing such an endpoint.
Description
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityNetwork-reachable, unauthenticated remote code execution with a CVSS of 9.8 and very high EPSS plus a public exploit.
What it is
Spring Framework versions 5.0 before 5.0.5 and 4.3 before 4.3.15 (plus older unsupported versions) allow applications to expose STOMP over WebSocket endpoints backed by a simple in-memory STOMP broker via spring-messaging. A crafted message to that broker can lead to remote code execution. Because the flaw is reachable over the network without credentials, it is a serious risk for any application exposing such an endpoint.
Impact
An unauthenticated attacker can execute arbitrary code in the context of the application server, giving full control of the host and any data or credentials it can reach.
Attack surface
Reached over the network through an exposed STOMP-over-WebSocket endpoint using the in-memory broker; the CVSS vector indicates no privileges and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.775 probability, 99.5th percentile) and a public Exploit-DB entry (44796) exists, indicating mature public exploitation.
What to do
- Upgrade Spring Framework to 5.0.5 or 4.3.15 (or later supported release) and apply vendor patches from Oracle, Red Hat and Debian advisories.
- If upgrading is not immediately possible, disable or remove the simple in-memory STOMP broker and avoid exposing STOMP over WebSocket endpoints to untrusted networks.
- Restrict network access to WebSocket/STOMP endpoints with firewalls, reverse proxies or authentication so only trusted clients can reach the broker.
- Inventory applications using spring-messaging and STOMP over WebSocket, including embedded copies in Oracle and other vendor products, and track their patch status.
Detection
- Monitor WebSocket and STOMP traffic for anomalous or malformed frames targeting broker destinations, especially unexpected subscription or send patterns.
- Alert on unexpected child processes, outbound connections or file writes originating from Java application servers hosting Spring WebSocket endpoints.
- Search application and server logs for STOMP broker errors, deserialization exceptions or unusual message-handling failures around WebSocket sessions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-1270 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1270), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.