A critical RCE vulnerability (CVSS 9.8) in the Spring Framework, the most widely-used Java web framework globally. Actively exploited within 24 hours of disclosure including deployment of Mirai botnet agents. CISA added it to the Known Exploited Vulnerabilities catalog immediately.
VULN_RECENT_FREQUENCY + maintainer health preconditions
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | VULN_RECENT_FREQUENCY + maintainer health preconditions |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; reactive not proactive |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |