CVE-2022-22963CISA KEVEPSS p100.0%

CVE-2022-22963VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

VMware Tanzu / Spring Cloud

Description

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Scoring

EPSS99.94% probability of exploitation · percentile 100.0% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-08-25

(incoming)1

TypeTargetConfidenceTier
KEVEntryVMware Tanzu Spring Cloud Function Remote Code Execution Vulnerabilitykev-cve-2022-229630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
VMware Spring Cloud Gateway Code Injection Vulnerability
CVE
Spring Framework JDK 9+ Remote Code Execution Vulnerability
CVE
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
CVE
CVE-2018-1273
CVE
CVE-2026-21532
CVE
VMware vCenter Server Remote Code Execution Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.