{"id":"CVE-2016-1000027","title":"Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data","summary":"Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not oc…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework < 6.0.0"],"patched":["spring_framework 6.0.0"],"published":"2020-01-02","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:10.483","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000027","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","label":"cve@mitre.org"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","label":"cve@mitre.org"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","label":"cve@mitre.org"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","label":"cve@mitre.org"},{"url":"https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json","label":"cve@mitre.org"},{"url":"https://security-tracker.debian.org/tracker/CVE-2016-1000027","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20230420-0009/","label":"cve@mitre.org"},{"url":"https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now","label":"cve@mitre.org"},{"url":"https://www.tenable.com/security/research/tra-2016-20","label":"cve@mitre.org"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security-tracker.debian.org/tracker/CVE-2016-1000027","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230420-0009/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/research/tra-2016-20","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T18:42:36.058466Z"},"epss":0.33179,"epssPercentile":0.98327,"exploits":{"github":4,"githubRepos":["https://github.com/artem-smotrakov/cve-2016-1000027-poc","https://github.com/tina94happy/Spring-Web-5xx-Mitigated-version","https://github.com/yihtserns/spring-web-without-remoting"],"checkedAt":"2026-10-07T19:44:51.102Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T19:44:15.637Z","slug":"CVE-2016-1000027","body":"## Overview\n\nPivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.\n\n## Affected\n\n- `spring_framework < 6.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 6.0.0`","depth":"abyssal","depthScore":73,"depthScoreParts":{"impact":53.9,"likelihood":6.6,"exploitation":12,"ransomware":0},"changes":[]}