← Global Threat Landscape

CVE-2022-22965

CWE-94

Critical

103.8

RPS

Description

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
99.63%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Apr 2022
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-94
Published
2 Apr 2022
Last modified 30 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-22965

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2022-22965 · RPS 103.8 · DevSecure Intelligence