---
id: CVE-2016-1000027
title: >-
  Pivotal Spring Framework through 5.3.16 suffers from a potential remote code
  execution (RCE) issue if used for Java deserialization of untrusted data
summary: >-
  Pivotal Spring Framework through 5.3.16 suffers from a potential remote code
  execution (RCE) issue if used for Java deserialization of untrusted data.
  Depending on how the library is implemented within a product, this issue may
  or not oc…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: vmware
product: spring_framework
affected:
  - spring_framework < 6.0.0
patched:
  - spring_framework 6.0.0
published: '2020-01-02'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:10.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-1000027'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027'
    label: cve@mitre.org
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626
    label: cve@mitre.org
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417
    label: cve@mitre.org
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525
    label: cve@mitre.org
  - url: >-
      https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json
    label: cve@mitre.org
  - url: 'https://security-tracker.debian.org/tracker/CVE-2016-1000027'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20230420-0009/'
    label: cve@mitre.org
  - url: >-
      https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now
    label: cve@mitre.org
  - url: 'https://www.tenable.com/security/research/tra-2016-20'
    label: cve@mitre.org
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000027'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-579669626
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-582313417
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/spring-projects/spring-framework/issues/24434#issuecomment-744519525
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.json
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security-tracker.debian.org/tracker/CVE-2016-1000027'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230420-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-now
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/research/tra-2016-20'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T18:42:36.058466Z'
epss: 0.33179
epssPercentile: 0.98327
exploits:
  github: 4
  githubRepos:
    - 'https://github.com/artem-smotrakov/cve-2016-1000027-poc'
    - 'https://github.com/tina94happy/Spring-Web-5xx-Mitigated-version'
    - 'https://github.com/yihtserns/spring-web-without-remoting'
  checkedAt: '2026-10-07T19:44:51.102Z'
exploitAvailable: true
ingestedAt: '2026-10-07T19:44:15.637Z'
---

## Overview

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

## Affected

- `spring_framework < 6.0.0`

## Remediation

Upgrade past the affected range:

- `spring_framework 6.0.0`
