VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago

CVE-2016-1000027

9.8 Critical Protected by RASP

Description

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CWE-502 · Deserialization of untrusted data

Exploitation Status

Proof of concept only

A proof of concept exists, but no reviewed exploit catalogue carries this CVE. Demonstrating a defect and weaponising it are different amounts of work.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 4 indexed Published artifacts you can open, in GitHub PoC; first seen 2021-02-01.
  • EPSS 32% chance in 30 days A model prediction, not an observation. Higher than 98% of all scored CVEs.

3 of these are GitHub repositories below the 5★ evidence bar. They are listed because a person may still want to open one; they do not count toward the exploit maturity above.

IndexArtifactStarsFirst seen
GitHub PoC PoC for CVE-2016-1000027 12 2021-02-01
GitHub PoC Mitigated version for CVE-2016-1000027 spring web. 2 2023-11-20
GitHub PoC validation de l'exploitabilité d'une CVE 2026-02-13
GitHub PoC Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027. 2024-02-08

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Marchal RCE rule.

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review human manual-review
  • Record active
Decided by manual-classification : A researcher's recorded decision for this specific CVE
Finding A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Marchal RCE rule.

Waratek research note

written 2026-09-14

Written by a Waratek engineer reviewing this CVE. A written classification sets the status directly, ahead of every automated scope rule except a withdrawal.

Comments

Rule Name: Marchal RCE rule

CVSS

9.8 CRITICAL v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H NVD Primary published
CVSS 2.0 7.5 no band published AV:N/AC:L/Au:N/C:P/I:P/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update January 2025 CPU 2025-Q1 Oracle Analytics / Development Operations (Spring Framework) (7.0.0.0.0, 7.6.0.0.0)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Analytics Development Operations (Spring Framework) 7.0.0.0.0, 7.6.0.0.0 7.0.0.0.0 · 7.6.0.0.0

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.springframework:spring-web 0 6.0.0 unbounded

🖥️ Product CPEs & Version Ranges

2 product(s) over 2 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
osv org.springframework spring-web generic < 6.0.0
nvd vmware spring framework generic < 6.0.0

References

URLTags
https://github.com/spring-projects/spring-framework/issues/21680 WEB
https://github.com/spring-projects/spring-framework/issues/24434 WEB
https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-1231625331 WEB
https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626 WEB
https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417 WEB
https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525 WEB
https://github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60f WEB
https://github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfa WEB
https://www.tenable.com/security/research/tra-2016-20 WEB
https://support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027 WEB

Timeline

Published 2020-01-02 Last modified 2026-06-17
Published2020-01-02By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.
Classification created2026-09-14First commit adding this CVE's research note.
Last VRT activity2026-09-14Most recent commit touching this CVE's classification, patch or rule file.