CVE advisoryCRITICAL
CVE-2016-1000027
Spring Framework Java Deserialization Vulnerability.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
The Spring Framework contains a Java deserialization vulnerability that may allow remote code execution if it processes untrusted data. The actual risk depends on how the framework is implemented, and whether authentication is required.