What happened
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
Affected versions
Bourne-Again Shell (Bash): See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 38849Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2015-12-02VerifiedExploit-DB 34777GNU Bash - Environment Variable Command Injection (Metasploit)Shaun Colley2014-09-25VerifiedExploit-DB 39918IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2016-06-10VerifiedExploit-DB 34895Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)Fady Mohammed Osman2014-10-06VerifiedExploit-DB 34839IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code InjectionClaudio Viviani2014-10-01VerifiedExploit-DB 36503QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 36504QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 40619TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command InjectionHacker Fantastic2016-10-21VerifiedExploit-DB 40938RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command InjectionHacker Fantastic2016-12-18VerifiedExploit-DB 34900Apache mod_cgi - 'Shellshock' Remote Command InjectionFederico Galatolo2014-10-06VerifiedExploit-DB 34766Bash - 'Shellshock' Environment Variables Command InjectionPrakhar Prasad & Subho Halder2014-09-25VerifiedExploit-DB 35115CUPS Filter - Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-29VerifiedExploit-DB 34765GNU Bash - 'Shellshock' Environment Variable Command InjectionStephane Chazelas2014-09-25VerifiedExploit-DB 34860GNU bash 4.3.11 - Environment Variable dhclient@0x00string2014-10-02VerifiedExploit-DB 34879OpenVPN 2.2.29 - 'Shellshock' Remote Command Injectionhobbily plunt2014-10-04VerifiedExploit-DB 34896Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command InjectionPhil Blank2014-10-06VerifiedExploit-DB 34862Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-02VerifiedExploit-DB 42938Qmail SMTP - Bash Environment Variable Injection (Metasploit)Metasploit2017-10-02VerifiedExploit-DB 37816Cisco Unified Communications Manager - Multiple VulnerabilitiesBernhard Mueller2015-08-18VerifiedExploit-DB 36609Kemp Load Master 7.1.16 - Multiple VulnerabilitiesRoberto Suggi Liverani2015-04-02VerifiedExploit-DB 35146PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command InjectionRyan King (Starfall)2014-11-03VerifiedSploitusNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.KitPloit2026-08-31T07:37:25Candidatekitploit.comNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.ru2026-08-31T07:37:25CandidatePoC-in-GitHub · dlitz/bash-cve-2014-6271-fixesCollected fixes for bash CVE-2014-6271★ 0dlitz2014-09-24CandidatePoC-in-GitHub · npm/ansible-bashpocalypsePatch for CVE-2014-6271★ 6npm2014-09-24CandidatePoC-in-GitHub · ryancnelson/patched-bash-4.3patched-bash-4.3 for CVE-2014-6271★ 0ryancnelson2014-09-24CandidatePoC-in-GitHub · jblaine/cookbook-bash-CVE-2014-6271Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271★ 0jblaine2014-09-25CandidatePoC-in-GitHub · rrreeeyyy/cve-2014-6271-spec★ 0rrreeeyyy2014-09-25CandidatePoC-in-GitHub · scottjpack/shellshock_scannerPython Scanner for "ShellShock" (CVE-2014-6271)★ 46scottjpack2014-09-25CandidatePoC-in-GitHub · Anklebiter87/Cgi-bin_bash_ReverseWritten fro CVE-2014-6271★ 1Anklebiter872014-09-25CandidatePoC-in-GitHub · justzx2011/bash-upa auto script to fix CVE-2014-6271 bash vulnerability★ 0justzx20112014-09-25CandidatePoC-in-GitHub · mattclegg/CVE-2014-6271★ 0mattclegg2014-09-25CandidatePoC-in-GitHub · ilismal/Nessus_CVE-2014-6271_checkQuick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271★ 0ilismal2014-09-25CandidatePoC-in-GitHub · RainMak3r/RainstormCVE-2014-6271 RCE tool★ 2RainMak3r2014-09-25CandidatePoC-in-GitHub · gabemarshall/shocknawwSimple script to check for CVE-2014-6271★ 1gabemarshall2014-09-25CandidatePoC-in-GitHub · woltage/CVE-2014-6271★ 0woltage2014-09-25CandidatePoC-in-GitHub · ariarijp/vagrant-shellshockCVE-2014-6271の検証用Vagrantfileです★ 0ariarijp2014-09-25CandidatePoC-in-GitHub · themson/shellshockscripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271★ 1themson2014-09-25CandidatePoC-in-GitHub · securusglobal/BadBashCVE-2014-6271 (ShellShock) RCE PoC tool★ 4securusglobal2014-09-26CandidatePoC-in-GitHub · villadora/CVE-2014-6271scaner for cve-2014-6271★ 0villadora2014-09-26CandidatePoC-in-GitHub · APSL/salt-shellshockSalt recipe for shellshock (CVE-2014-6271)★ 1APSL2014-09-26CandidatePoC-in-GitHub · teedeedubya/bash-fix-exploitAnsible role to check the CVE-2014-6271 vulnerability★ 0teedeedubya2014-09-26CandidatePoC-in-GitHub · internero/debian-lenny-bash_3.2.52-cve-2014-6271Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)★ 0internero2014-09-26CandidatePoC-in-GitHub · u20024804/bash-3.2-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · u20024804/bash-4.2-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · u20024804/bash-4.3-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · francisck/shellshock-cgiA python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server★ 12francisck2014-09-28CandidatePoC-in-GitHub · proclnas/ShellShock-CGI-ScanA script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)★ 1proclnas2014-09-28CandidatePoC-in-GitHub · sch3m4/RISCVE-2014-6271 Remote Interactive Shell - PoC Exploit★ 2sch3m42014-09-29CandidatePoC-in-GitHub · ryeyao/CVE-2014-6271_Test★ 1ryeyao2014-09-29CandidatePoC-in-GitHub · cj1324/CGIShellshellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI★ 13cj13242014-09-29CandidatePoC-in-GitHub · renanvicente/puppet-shellshockThis module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible★ 0renanvicente2014-09-29CandidatePoC-in-GitHub · indiandragon/Shellshock-Vulnerability-ScanAndroid app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock★ 11indiandragon2014-10-03CandidatePoC-in-GitHub · ramnes/pyshellshock:scream: Python library and utility for CVE-2014-6271 (aka. "shellshock")★ 2ramnes2014-11-06CandidatePoC-in-GitHub · akiraaisha/shellshocker-pythonThis is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271★ 3akiraaisha2015-02-22CandidatePoC-in-GitHub · 352926/shellshock_crawlerUsing google to scan sites for "ShellShock" (CVE-2014-6271)★ 03529262015-03-20CandidatePoC-in-GitHub · kelleykong/cve-2014-6271-mengjia-kongsystem reading course★ 0kelleykong2015-06-06CandidatePoC-in-GitHub · huanlu/cve-2014-6271-huan-lureading course★ 0huanlu2015-06-10CandidatePoC-in-GitHub · sunnyjiang/shellshocker-androidThis is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271★ 1sunnyjiang2015-06-17CandidatePoC-in-GitHub · P0cL4bs/ShellShock-CGI-ScanA script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).★ 6P0cL4bs2015-06-26CandidatePoC-in-GitHub · hmlio/vaas-cve-2014-6271Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock★ 22hmlio2015-07-11CandidatePoC-in-GitHub · opsxcq/exploit-CVE-2014-6271Shellshock exploit + vulnerable environment★ 232opsxcq2016-12-07CandidatePoC-in-GitHub · Pilou-Pilou/docker_CVE-2014-6271.★ 0Pilou-Pilou2017-01-25CandidatePoC-in-GitHub · zalalov/CVE-2014-6271Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell★ 4zalalov2017-04-30CandidatePoC-in-GitHub · heikipikker/shellshock-shellA simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.★ 0heikipikker2017-10-17CandidatePoC-in-GitHub · 0x00-0x00/CVE-2014-6271Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.★ 30x00-0x002017-11-23CandidatePoC-in-GitHub · kowshik-sundararajan/CVE-2014-6271CS4238 Computer Security Practices★ 0kowshik-sundararajan2018-05-05CandidatePoC-in-GitHub · w4fz5uck5/ShockZaum-CVE-2014-6271Shellshock vulnerability attacker★ 0w4fz5uck52018-06-18CandidatePoC-in-GitHub · Aruthw/CVE-2014-6271★ 0Aruthw2018-06-30CandidatePoC-in-GitHub · cved-sources/cve-2014-6271cve-2014-6271★ 0cved-sources2019-01-06CandidatePoC-in-GitHub · shawntns/exploit-CVE-2014-6271★ 0shawntns2019-04-27CandidatePoC-in-GitHub · Sindadziy/cve-2014-6271★ 0Sindadziy2019-11-12CandidatePoC-in-GitHub · wenyu1999/bash-shellshockcve-2014-6271★ 0wenyu19992019-11-13CandidatePoC-in-GitHub · Sindayifu/CVE-2019-14287-CVE-2014-6271★ 0Sindayifu2019-11-13CandidatePoC-in-GitHub · Any3ite/CVE-2014-6271★ 1Any3ite2020-01-06CandidatePoC-in-GitHub · somhm-solutions/Shell-Shock*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---★ 1somhm-solutions2020-01-28CandidatePoC-in-GitHub · rashmikadileeshara/CVE-2014-6271-Shellshock-This is an individual assignment for secure network programming★ 0rashmikadileeshara2020-05-12CandidatePoC-in-GitHub · Dilith006/CVE-2014-6271★ 0Dilith0062020-05-12CandidatePoC-in-GitHub · cyberharsh/Shellbash-CVE-2014-6271★ 0cyberharsh2020-06-26CandidatePoC-in-GitHub · MuirlandOracle/CVE-2014-6271-IPFire★ 0MuirlandOracle2020-11-12CandidatePoC-in-GitHub · mochizuki875/CVE-2014-6271-Apache-DebianThis Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).★ 1mochizuki8752021-07-24CandidatePoC-in-GitHub · b4keSn4ke/CVE-2014-6271Shellshock exploit aka CVE-2014-6271★ 15b4keSn4ke2021-07-29CandidatePoC-in-GitHub · akr3ch/CVE-2014-6271ShellShock interactive-shell exploit★ 4akr3ch2022-04-02CandidatePoC-in-GitHub · Gurguii/cgi-bin-shellshock[Python/Shell] - Tested in HackTheBox - Shocker (Easy) CVE-2014-6271★ 1Gurguii2022-06-23CandidatePoC-in-GitHub · anujbhan/shellshock-victim-hostA docker container vulnerable to Shellshock - CVE-2014-6271★ 0anujbhan2022-06-27CandidatePoC-in-GitHub · FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing★ 0FilipStudeny2022-09-09CandidatePoC-in-GitHub · mritunjay-k/CVE-2014-6271★ 0mritunjay-k2023-03-02CandidatePoC-in-GitHub · Brandaoo/CVE-2014-6271★ 0Brandaoo2023-03-25CandidatePoC-in-GitHub · J0hnTh3Kn1ght/CVE-2014-6271Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi★ 5J0hnTh3Kn1ght2023-07-01CandidatePoC-in-GitHub · hanmin0512/CVE-2014-6271_pwnable★ 0hanmin05122023-08-29CandidatePoC-in-GitHub · 0xN7y/CVE-2014-6271EXPLOIT FOR CVE-2014-6271★ 10xN7y2023-10-31CandidatePoC-in-GitHub · AlissonFaoli/ShellshockShellshock exploit (CVE-2014-6271)★ 0AlissonFaoli2024-02-04CandidatePoC-in-GitHub · ajansha/shellshockShelly is a lightweight and efficient vulnerability scanner designed to identify and mitigate Shellshock (CVE-2014-6271 & CVE-2014-7169) vulnerabilities in Bash environments.★ 0ajansha2024-05-10CandidatePoC-in-GitHub · K3ysTr0K3R/CVE-2014-6271-EXPLOITA PoC exploit for CVE-2014-6271 - Shellshock★ 4K3ysTr0K3R2024-05-18CandidatePoC-in-GitHub · TheRealCiscoo/shellshock-pocPrueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).★ 1TheRealCiscoo2024-07-14CandidatePoC-in-GitHub · RadYio/CVE-2014-6271Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible★ 1RadYio2024-11-26CandidatePoC-in-GitHub · YunchoHang/CVE-2014-6271-SHELLSHOCKAutomation script to exploit the Shellshock vulnerability.★ 0YunchoHang2025-02-26CandidatePoC-in-GitHub · moften/CVE-2014-6271Shellshock Vulnerability Scanner★ 0moften2025-05-05CandidatePoC-in-GitHub · knightc0de/Shellshock_vuln_ExploitCVE-2014-6271(RCE) poc Exploit★ 0knightc0de2025-06-14CandidatePoC-in-GitHub · rsherstnev/CVE-2014-6271This is my implementation of shellshock exploit★ 0rsherstnev2025-07-25CandidatePoC-in-GitHub · RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis★ 0RAJMadhusankha2025-08-09CandidatePoC-in-GitHub · DrHaitham/CVE-2014-6271-Shellshock-A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.★ 0DrHaitham2025-12-05CandidatePoC-in-GitHub · mtaha-sec/bash-apocalypseRecreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite methodology + Docker lab. Built for security research & education. Offensive security portfolio project.★ 0mtaha-sec2025-12-06CandidatePoC-in-GitHub · andres101c/Shellshock-CVE-2014-6271★ 0andres101c2026-02-17CandidatePoC-in-GitHub · Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-ShellshockCVE-2014-6271 Exploit | by infrar3d★ 0Industri4l-H3ll-Xpl0it3rs2026-02-19CandidatePoC-in-GitHub · 0xBlackash/CVE-2014-6271CVE-2014-6271★ 00xBlackash2026-03-06CandidatePoC-in-GitHub · ambjlou/it355-lab4-enterprise-lan-securityThis repository contains a comprehensive security assessment of an enterprise LAN environment. The core focus of this project was the identification, exploitation, and remediation of the **Shellshock (CVE-2014-6271)** vulnerability within a Linux-based web server.★ 0ambjlou2026-04-02CandidatePoC-in-GitHub · kaleth4/-CVE-2014-6271★ 0kaleth42026-04-09CandidatePoC-in-GitHub · kaleth4/CVE-2014-6271★ 0kaleth42026-04-09CandidatePoC-in-GitHub · V3nG4mxV1p3r/Mobile-Drop-Device-SOC-DetectionEnd-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).★ 1V3nG4mxV1p3r2026-04-22CandidatePoC-in-GitHub · im2sinister/CVE-2014-6271its simple Shellshock exploit★ 1im2sinister2026-04-24CandidatePoC-in-GitHub · HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-ThorBlack-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.★ 0HevenTafese2026-04-30CandidatePoC-in-GitHub · FacundoMfernandez/pentesting-obiobaPentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico★ 0FacundoMfernandez2026-05-05CandidatePoC-in-GitHub · R3fr4kt/Shocker-TJNULL-OSCP-"A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors."★ 0R3fr4kt2026-06-02CandidatePoC-in-GitHub · cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-ReportThis repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.★ 0cyberexpert1112026-07-05CandidatePoC-in-GitHub · caverm/Shellshock_CVE-2014-6271Shellshock★ 0caverm2026-07-07CandidatePoC-in-GitHub · FREEGUY-6/dmz-security-monitoring-hardeningCY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271★ 1FREEGUY-62026-08-03CandidatePoC-in-GitHub · Vaibhav91one/shellshock-cve-labShellshock CVE-2014-6271 vulnerable CGI lab★ 0Vaibhav91one2026-08-30CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.