Spring Boot Actuator Sensitive Endpoint Probe for 2026-09-08
Sep 08, 2026
Exploitation
Last Updated: 00:00 UTC
Spring Boot Actuator exposes management endpoints. heapdump returns a full JVM heap snapshot containing in-memory secrets. env returns all environment variables. gateway/routes is the RCE precursor for CVE-2022-22947 (Spring Cloud Gateway SPEL injection).
CVE References
MITRE ATT&CK
Tactic: Discovery (TA0007)
Technique: T1046 — Network Service Scanning
Observed URIs
Attackers by Country
| Japan | 2 | 50.0% |
| Germany | 1 | 25.0% |
| Netherlands | 1 | 25.0% |
IP Address : ASN : City/Provider
-
34.141.123.60 : AS396982 google : Frankfurt am Main
-
34.84.82.204 : AS396982 google : Tokyo
-
34.97.175.217 : AS396982 google : Osaka
-
35.234.46.196 : unknown : unknown
-
81.171.72.93 : ASNone : Netherlands