CVE-2018-1270 is an improper-input-validation vulnerability in the Spring Framework spring-messaging module. It affects applications exposing STOMP-over-WebSocket endpoints backed by the simple in-memory STOMP broker in Spring Framework 5.0 releases before 5.0.5, 4.3 releases before 4.3.15, and older unsupported releases. A malicious user can send a crafted message to the broker that can result in remote code execution. The initial remediation was incomplete for the 4.3.x branch, which was subsequently addressed by CVE-2018-1275.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2018-1270, a remote code execution vulnerability in Spring Framework's spring-messaging module when used with WebSocket and STOMP. The vulnerability arises from unsafe use of the StandardEvaluationContext, allowing attackers to inject and execute arbitrary SpEL (Spring Expression Language) expressions via the STOMP 'selector' header. The repository contains a Java Spring Boot server implementing a WebSocket STOMP endpoint ('/hello') and a client that connects to it. The static web interface (index.html and app.js) allows users to input arbitrary SpEL expressions, which are sent as selectors in STOMP subscriptions. The exploit demonstrates how an attacker can execute system commands (e.g., copying /etc/passwd) on the server by crafting a malicious selector. The codebase is structured as a typical Spring Boot application with separate modules for the server, client, and static web resources. The main attack vector is network-based, targeting the WebSocket STOMP endpoint. The repository is a functional POC and does not include weaponized or automated exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A possible remote-code-execution vulnerability in Spring Framework through Spring Messaging.
A previously identified Spring Framework vulnerability referenced because CVE-2018-1275 addresses a partial fix for it.
A dependency vulnerability identified for remediation through library updates in Apache Geode geode-core 1.12.0.
A preceding Spring Framework vulnerability for which CVE-2018-1275 corrects a partial fix in the 4.3.x branch. The content provides no further technical details.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.