Spring Boot Actuator Sensitive Endpoint Probe for 2026-10-04

Last Updated: 00:00 UTC

Spring Boot Actuator exposes management endpoints. heapdump returns a full JVM heap snapshot containing in-memory secrets. env returns all environment variables. gateway/routes is the RCE precursor for CVE-2022-22947 (Spring Cloud Gateway SPEL injection).

CVE References

CVE-2022-22947

MITRE ATT&CK

Tactic: Discovery (TA0007)
Technique: T1046 — Network Service Scanning

Observed URIs

Attackers by Country

United States of America: 5Germany: 1Belgium: 1
United States of America571.4%
Germany114.3%
Belgium114.3%

IP Address : ASN : City/Provider

  • 159.223.132.86 : AS14061 digitalocean llc : United States of America

  • 206.81.12.187 : AS14061 digitalocean llc : North Bergen

  • 213.209.159.133 : AS42821 k&k kommunikationssysteme gmbh : Germany

  • 34.179.164.52 : AS15169 google llc : United States of America

  • 34.23.147.147 : ASNone : United States of America

  • 34.6.78.29 : ASNone : United States of America

  • 34.79.23.116 : AS396982 google : Brussels

  • 34.80.89.28 : unknown : unknown

Share on: