← Vulnerability feed

Vulnerability record · CVE-2022-42889 · published 13 October 2022

CVE-2022-42889: Apache Commons Text interpolation allows remote code execution

Apache · Commons Text

Apache Commons Text versions 1.5 through 1.9 enable default StringLookup interpolators (script, dns, url) that can execute code or contact remote servers when untrusted values are interpolated. Applications relying on the default interpolation behavior are exposed to remote code execution. The flaw is fixed in 1.10.0, which disables the problematic interpolators by default.

9.8 CVSS 3.1 Critical EPSS 100% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and near-maximum EPSS make this a top remediation target despite absence from KEV.

What it is

Apache Commons Text versions 1.5 through 1.9 enable default StringLookup interpolators (script, dns, url) that can execute code or contact remote servers when untrusted values are interpolated. Applications relying on the default interpolation behavior are exposed to remote code execution. The flaw is fixed in 1.10.0, which disables the problematic interpolators by default.

Impact

An attacker who can influence interpolated input can execute arbitrary code in the JVM or force outbound requests to attacker-controlled or internal systems. This yields full compromise of confidentiality, integrity and availability of the affected application.

Attack surface

Reached over the network through any application path that passes untrusted configuration or user-supplied values into Commons Text interpolation. The CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is near maximum (0.99931, 99.969th percentile) and public references include a Packet Storm remote code execution write-up, indicating active interest and likely exploit availability.

What to do

  • Upgrade Apache Commons Text to 1.10.0 or later, which disables the script, dns and url interpolators by default.
  • If immediate upgrade is not possible, remove or restrict the default interpolators by constructing a custom StringSubstitutor with an explicit, minimal StringLookup set.
  • Audit application code and configuration for untrusted values passed into StringSubstitutor or interpolated strings, and sanitize or reject ${...} patterns from external input.
  • Track vendor advisories for bundled products (NetApp BlueXP, Juniper Security Threat Response Manager) and apply their patched releases.
  • Restrict outbound network access from application servers to limit dns and url lookup abuse.

Detection

  • Search application and dependency inventories for Apache Commons Text versions 1.5 through 1.9.
  • Monitor logs and process telemetry for JVM script engine invocation or unexpected child processes spawned by Java applications.
  • Alert on outbound DNS or HTTP requests originating from application servers to unusual or internal destinations.
  • Inspect request and configuration inputs for ${script:, ${dns: or ${url: interpolation patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2023/Feb/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/10/13/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/10/18/1 Mailing ListThird Party Advisory
https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om Mailing ListVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022 Third Party Advisory
https://security.gentoo.org/glsa/202301-05 Third Party Advisory
https://security.netapp.com/advisory/ntap-20221020-0004/ Third Party Advisory
http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2023/Feb/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/10/13/4 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2022/10/18/1 Mailing ListThird Party Advisory
https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om Mailing ListVendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0022 Third Party Advisory
https://security.gentoo.org/glsa/202301-05 Third Party Advisory
https://security.netapp.com/advisory/ntap-20221020-0004/ Third Party Advisory

Track CVE-2022-42889 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2024-7254Google protobuf uncontrolled resource consumption vulnerabilityAny project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exce…EPSS 2.8%7.5CVE-2024-25111Squid HTTP chunked decoder recursion denial of serviceSquid versions 3.5.27 through 6.7 contain an uncontrolled recursion bug in the HTTP chunked decoder. A remote attacker can send a crafted chunked-enc…EPSS 65%analysed7.5CVE-2024-22201Eclipse jetty uncontrolled resource consumption vulnerabilityJetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out.…EPSS 1.4%7.5CVE-2024-25617Squid HTTP header parsing denial of service via oversized headersSquid, the open source caching proxy, mishandles oversized HTTP headers due to a Collapse of Data into Unsafe Value bug in header parsing. A remote c…EPSS 88%analysed7.4CVE-2024-21147Netapp active iq unified manager information exposure vulnerabilityVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppor…EPSS 1.1%4.9CVE-2024-21055Oracle mysql uncontrolled resource consumption vulnerabilityVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior. …EPSS 0.89%4.8CVE-2024-21140Netapp active iq unified manager information exposure vulnerabilityVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Suppor…EPSS 0.94%4.8CVE-2024-21145Oracle graalvm improper access control vulnerabilityVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported v…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2022-42889), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.