Critical severity9.8NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026
CVE-2016-1000027
CVE-2016-1000027
Description
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-webMaven | < 6.0.0 | 6.0.0 |
Affected products
28- Pivotal/Spring Frameworkdescription
- osv-coords26 versionspkg:apk/chainguard/apache-nifipkg:apk/chainguard/apache-nifi-compatpkg:apk/chainguard/apache-nifi-toolkitpkg:apk/chainguard/geoserver-2.26pkg:apk/chainguard/geoserver-2.26-communitypkg:apk/chainguard/geoserver-2.26-dockerpkg:apk/chainguard/geoserver-2.27pkg:apk/chainguard/geoserver-2.27-communitypkg:apk/chainguard/geoserver-2.27-dockerpkg:apk/chainguard/geoserver-2.28pkg:apk/chainguard/geoserver-2.28-communitypkg:apk/chainguard/jenkinspkg:apk/chainguard/jenkins-2.440pkg:apk/chainguard/jenkins-2.452pkg:apk/chainguard/jenkins-2.462pkg:apk/chainguard/jenkins-compatpkg:apk/chainguard/jenkins-remotingpkg:apk/chainguard/ontoppkg:apk/chainguard/ontop-fipspkg:apk/wolfi/apache-nifipkg:apk/wolfi/apache-nifi-compatpkg:apk/wolfi/apache-nifi-toolkitpkg:apk/wolfi/jenkinspkg:apk/wolfi/jenkins-compatpkg:apk/wolfi/jenkins-remotingpkg:maven/org.springframework/spring-web
< 0+ 25 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 2.28.3-r0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 6.0.0
Patches
Vulnerability mechanics
References
19- raw.githubusercontent.com/distributedweaknessfiling/cvelist/master/2016/1000xxx/CVE-2016-1000027.jsonnvdBroken LinkExploitThird Party Advisory
- www.tenable.com/security/research/tra-2016-20nvdExploitThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-4wrc-f8pq-fpqpghsaADVISORY
- github.com/spring-projects/spring-framework/issues/24434nvdIssue TrackingThird Party AdvisoryWEB
- github.com/spring-projects/spring-framework/issues/24434nvdIssue TrackingThird Party AdvisoryWEB
- github.com/spring-projects/spring-framework/issues/24434nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-1000027ghsaADVISORY
- security-tracker.debian.org/tracker/CVE-2016-1000027nvdThird Party AdvisoryWEB
- spring.io/blog/2022/05/11/spring-framework-5-3-20-and-5-2-22-available-nownvdRelease NotesThird Party AdvisoryWEB
- github.com/spring-projects/spring-framework/commit/2b051b8b321768a4cfef83077db65c6328ffd60fghsaWEB
- github.com/spring-projects/spring-framework/commit/5cbe90b2cd91b866a5a9586e460f311860e11cfaghsaWEB
- github.com/spring-projects/spring-framework/issues/21680ghsaWEB
- github.com/spring-projects/spring-framework/issues/24434ghsaWEB
- github.com/spring-projects/spring-framework/issues/24434ghsaWEB
- jira.spring.io/browse/SPR-17143ghsaWEB
- security.netapp.com/advisory/ntap-20230420-0009ghsaWEB
- support.contrastsecurity.com/hc/en-us/articles/4402400830612-Spring-web-Java-Deserialization-CVE-2016-1000027ghsaWEB
- security.netapp.com/advisory/ntap-20230420-0009/nvd
News mentions
0No linked articles in our index yet.