← Vulnerability feed

Vulnerability record · CVE-2022-22947 · published 3 March 2022

CVE-2022-22947: Spring Cloud Gateway Actuator endpoint code injection

Vmware · Spring Cloud Gateway

Spring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A crafted request can trigger expression language evaluation leading to arbitrary remote code execution. The flaw matters because it is network reachable, needs no authentication or user interaction, and has a maximum CVSS score of 10.0.

10.0 CVSS 3.1 Critical CISA KEV since 16 May 2022 EPSS 98% · top 0.1% CWE-94 · Code injectionCWE-917 · Expression language injection
10.0CVSS 3.1 base score, v2 6.8
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
11References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with CVSS 10.0, KEV listing and near-maximum EPSS makes this an urgent patch-first item.

What it is

Spring Cloud Gateway versions before 3.1.1+ and 3.0.7+ allow code injection when the Gateway Actuator endpoint is enabled, exposed and unsecured. A crafted request can trigger expression language evaluation leading to arbitrary remote code execution. The flaw matters because it is network reachable, needs no authentication or user interaction, and has a maximum CVSS score of 10.0.

Impact

An unauthenticated remote attacker can execute arbitrary code on the host running the gateway, giving full control of that process and its data. Because the CVSS scope is changed, compromise can extend beyond the gateway component itself.

Attack surface

Reached over the network via HTTP requests to the exposed Gateway Actuator endpoint; the vector shows no privileges and no user interaction required. Exposure depends on the Actuator endpoint being enabled, exposed and left unsecured.

Exploitation

Listed in CISA KEV since 2022-05-16 with a required action to apply vendor updates, and public exploit references exist. EPSS is 0.98253 (99.9th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Upgrade Spring Cloud Gateway to 3.1.1+ or 3.0.7+ (or later) per the VMware advisory, and apply the referenced Oracle CPU patches for affected Oracle products.
  • Disable the Gateway Actuator endpoint where it is not operationally required.
  • If the Actuator must run, restrict it to trusted management networks and require authentication; never expose it to the internet.
  • Audit gateway configuration and network exposure for unsecured Actuator routes, and remove any unnecessary management endpoints.
  • Monitor vendor advisories for updated fixed versions and re-check affected deployments.

Detection

  • Inspect gateway and reverse proxy logs for requests to Actuator routes, especially POST/PUT/DELETE to /actuator/gateway/routes and refresh endpoints.
  • Alert on unexpected outbound connections or child processes spawned by the gateway Java process.
  • Search for route definitions or Actuator responses containing expression language syntax such as SpEL or ${...} patterns.
  • Review gateway configuration changes and new route registrations for unauthorized additions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22947 to the Known Exploited Vulnerabilities catalog on 16 May 2022 as "VMware Spring Cloud Gateway Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 June 2022.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed9.9CVE-2026-61146Oracle commerce experience manager improper privilege management vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition Sy…EPSS 0.43%9.8CVE-2026-70995Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Con…EPSS 0.51%9.8CVE-2026-61161Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Con…EPSS 0.51%9.8CVE-2026-61145Oracle commerce experience manager improper access control vulnerabilityVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition Sy…EPSS 0.51%9.8CVE-2021-3773Linux kernel information exposure vulnerabilityA flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network …EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2022-22947), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.