Ross ROSS = Recommend OSS · open-source software intelligence for agents

AabyssZG/SpringBoot-Scan

针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具 observed · 2026-08-28

github.com/AabyssZG/SpringBoot-Scan · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

53/100

  • Activity 51
  • Release rhythm 32
  • Longevity 93
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 121.5
  • age_days: 1313
  • days_rel: 297
  • days_push: 297
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

2340 stars · 179 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensitive information-leakage endpoints and tests for a range of high-risk Spring-related CVEs such as Spring Core RCE (CVE-2022-22965) and Spring Cloud Gateway SpEL RCE (CVE-2022-22947).

Use cases

  • scan spring boot apps for sensitive actuator endpoints
  • test spring boot for known CVE exploits
  • check if a spring cloud gateway is vulnerable to CVE-2022-22947
  • bulk scan a list of urls for spring boot information leaks
  • export target assets from fofa or zoomeye for spring boot scanning
  • interactively run commands on a spring rce vulnerability
  • brute force spring boot endpoint directories

When to choose

  • you are doing authorized penetration testing against Spring Boot microservices
  • you need a single tool covering many Spring CVE exploit modules
  • you want batch scanning of URL lists for sensitive endpoint leaks

When to avoid

  • you need a general-purpose web vulnerability scanner beyond Spring
  • you require a GUI or continuous vulnerability management platform
  • your use case is defensive-only patch tracking rather than active testing

Facets

cli-tool · maturity active

penetration-testing vulnerability-scanning security web-scraping security penetration-testing web-development developer-tools python cli cross-platform spring-boot spring-vulnerabilities cve-exploitation sensitive-endpoint-scanning red-team offensive-security asset-mapping fofa zoomeye hunter

1 source

Member repositories

RepositoryRoleHealth v2
AabyssZG/SpringBoot-Scanmain53

For agents

markdown · JSON · MCP: product_card(name="AabyssZG/SpringBoot-Scan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem