← Vulnerability feed

Vulnerability record · CVE-2022-22963 · published 1 April 2022

CVE-2022-22963: Spring Cloud Function routing expression SpEL injection RCE

Vmware · Spring Cloud Function

Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression when routing functionality is enabled. The expression is evaluated server-side, leading to remote code execution and access to local resources. It is a critical, unauthenticated network-reachable flaw in a widely deployed Java framework.

9.8 CVSS 3.1 Critical CISA KEV since 25 Aug 2022 EPSS 100% · top 0.1% CWE-94 · Code injectionCWE-917 · Expression language injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
28Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a CVSS of 9.8, KEV listing and near-maximum EPSS probability.

What it is

Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression when routing functionality is enabled. The expression is evaluated server-side, leading to remote code execution and access to local resources. It is a critical, unauthenticated network-reachable flaw in a widely deployed Java framework.

Impact

An attacker gains remote code execution in the context of the application, allowing arbitrary command execution and access to local resources on the host.

Attack surface

Reached over the network via the routing functionality by supplying a malicious routing-expression; the CVSS vector shows no privileges or user interaction required.

Exploitation

Listed in CISA KEV since 2022-08-25 with a required action deadline of 2022-09-15, and EPSS 30-day probability is 0.99938 (99.97th percentile); references include an Exploit-tagged Packet Storm entry. No ransomware campaign use is documented.

What to do

  • Upgrade Spring Cloud Function to a fixed release per the VMware Tanzu advisory, and apply the Oracle CPU patches for affected Oracle products.
  • Disable or restrict the routing functionality if it is not required, and avoid evaluating user-supplied routing expressions.
  • Place affected services behind authentication and network controls so the routing endpoint is not exposed to untrusted clients.
  • Monitor vendor advisories and redeploy dependent Oracle and VMware products that bundle the affected library.

Detection

  • Inspect HTTP requests for routing-expression parameters or headers containing SpEL syntax such as T(, Runtime, or ProcessBuilder.
  • Alert on outbound network connections or process creation spawned by Java application servers hosting Spring Cloud Function.
  • Search application and WAF logs for anomalous expression strings or repeated requests to function routing endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22963 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22963 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-5413Vmware spring integration deserialization of untrusted data vulnerabilitySpring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default o…EPSS 4.4%9.8CVE-2019-0228Apache pdfbox xml external entity (xxe) vulnerabilityApache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…EPSS 9.5%8.8CVE-2021-29505XStream XML deserialization allows remote command executionXStream versions prior to 1.4.17 deserialize untrusted XML input without adequate type restrictions, allowing an attacker with sufficient rights to e…EPSS 77%analysed8.8CVE-2020-26217XStream blocklist bypass allows remote code executionXStream before 1.4.14 can be tricked into deserializing attacker-controlled input that leads to OS command execution. Only deployments relying on XSt…EPSS 85%analysed8.1CVE-2020-36183Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.…EPSS 4.9%8.1CVE-2020-36179Netapp cloud backup deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.common…EPSS 17%8.1CVE-2020-36180Netapp cloud backup deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbc…EPSS 4.0%8.1CVE-2020-36182Fasterxml jackson-databind deserialization of untrusted data vulnerabilityFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2022-22963), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.