Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-22950

43
FAUCET Score

CVE-2022-22950 is a denial-of-service vulnerability affecting Spring Framework versions 5.3.0 through 5.3.16 and older unsupported versions. An authenticated attacker can exploit this by submitting a specially crafted SpEL expression, leading to a denial of service. While no public exploit code is available, the vulnerability has garnered significant community attention and media coverage, with some initial confusion surrounding its relation to the more critical "Spring4Shell" vulnerability. This medium-severity flaw (CVSS 6.5) does not appear to be actively exploited in the wild, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.2.20CPE matchmatch criteria
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
>= 5.3.0, < 5.3.17CPE matchmatch criteria
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
35.83%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.3583 is in the 100th percentile among its peer group of 21,924 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

mavenpatch availablevia ghsa
Product: org.springframework:spring-expressionFixed in: 5.2.20.RELEASE
mavenpatch availablevia ghsa
Product: org.springframework:spring-expressionFixed in: 5.3.17
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-dependencies-0:4.5.2-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.0 asyncFixed in: spring-expression
View patch
redhatpatch availablevia redhat_api
Product: Text-Only RHOARFixed in: spring-expression
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11Fixed in: spring-expression
View patch
redhatno patchvia redhat_api
Product: Red Hat support for Spring BootFixed in: spring-expression
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: spring-expression
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: spring-expression
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: spring-expression
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: spring-expression

Vendor Advisories (2)

mavenGHSA-558x-2xjg-6232medium

Allocation of Resources Without Limits or Throttling in Spring Framework

Apr 3, 2022
redhatCVE-2022-22950Moderate

spring-expression: Denial of service via specially crafted SpEL expression

Mar 28, 2022

References

tanzu.vmware.com / security/cve-2022-22950
MitigationVendor Advisory