GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

Published 31 Aug 2026Updated 31 Aug 20262490 sources
CVSS 10.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

Affected versions

Bourne-Again Shell (Bash): See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 38849Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2015-12-02VerifiedExploit-DB 34777GNU Bash - Environment Variable Command Injection (Metasploit)Shaun Colley2014-09-25VerifiedExploit-DB 39918IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)Metasploit2016-06-10VerifiedExploit-DB 34895Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)Fady Mohammed Osman2014-10-06VerifiedExploit-DB 34839IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code InjectionClaudio Viviani2014-10-01VerifiedExploit-DB 36503QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 36504QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)Patrick Pellegrino2015-03-26VerifiedExploit-DB 40619TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command InjectionHacker Fantastic2016-10-21VerifiedExploit-DB 40938RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command InjectionHacker Fantastic2016-12-18VerifiedExploit-DB 34900Apache mod_cgi - 'Shellshock' Remote Command InjectionFederico Galatolo2014-10-06VerifiedExploit-DB 34766Bash - 'Shellshock' Environment Variables Command InjectionPrakhar Prasad & Subho Halder2014-09-25VerifiedExploit-DB 35115CUPS Filter - Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-29VerifiedExploit-DB 34765GNU Bash - 'Shellshock' Environment Variable Command InjectionStephane Chazelas2014-09-25VerifiedExploit-DB 34860GNU bash 4.3.11 - Environment Variable dhclient@0x00string2014-10-02VerifiedExploit-DB 34879OpenVPN 2.2.29 - 'Shellshock' Remote Command Injectionhobbily plunt2014-10-04VerifiedExploit-DB 34896Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command InjectionPhil Blank2014-10-06VerifiedExploit-DB 34862Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)Metasploit2014-10-02VerifiedExploit-DB 42938Qmail SMTP - Bash Environment Variable Injection (Metasploit)Metasploit2017-10-02VerifiedExploit-DB 37816Cisco Unified Communications Manager - Multiple VulnerabilitiesBernhard Mueller2015-08-18VerifiedExploit-DB 36609Kemp Load Master 7.1.16 - Multiple VulnerabilitiesRoberto Suggi Liverani2015-04-02VerifiedExploit-DB 35146PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command InjectionRyan King (Starfall)2014-11-03VerifiedSploitusNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.KitPloit2026-08-31T07:37:25Candidatekitploit.comNetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.ru2026-08-31T07:37:25CandidatePoC-in-GitHub · dlitz/bash-cve-2014-6271-fixesCollected fixes for bash CVE-2014-6271★ 0dlitz2014-09-24CandidatePoC-in-GitHub · npm/ansible-bashpocalypsePatch for CVE-2014-6271★ 6npm2014-09-24CandidatePoC-in-GitHub · ryancnelson/patched-bash-4.3patched-bash-4.3 for CVE-2014-6271★ 0ryancnelson2014-09-24CandidatePoC-in-GitHub · jblaine/cookbook-bash-CVE-2014-6271Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271★ 0jblaine2014-09-25CandidatePoC-in-GitHub · rrreeeyyy/cve-2014-6271-spec★ 0rrreeeyyy2014-09-25CandidatePoC-in-GitHub · scottjpack/shellshock_scannerPython Scanner for "ShellShock" (CVE-2014-6271)★ 46scottjpack2014-09-25CandidatePoC-in-GitHub · Anklebiter87/Cgi-bin_bash_ReverseWritten fro CVE-2014-6271★ 1Anklebiter872014-09-25CandidatePoC-in-GitHub · justzx2011/bash-upa auto script to fix CVE-2014-6271 bash vulnerability★ 0justzx20112014-09-25CandidatePoC-in-GitHub · mattclegg/CVE-2014-6271★ 0mattclegg2014-09-25CandidatePoC-in-GitHub · ilismal/Nessus_CVE-2014-6271_checkQuick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271★ 0ilismal2014-09-25CandidatePoC-in-GitHub · RainMak3r/RainstormCVE-2014-6271 RCE tool★ 2RainMak3r2014-09-25CandidatePoC-in-GitHub · gabemarshall/shocknawwSimple script to check for CVE-2014-6271★ 1gabemarshall2014-09-25CandidatePoC-in-GitHub · woltage/CVE-2014-6271★ 0woltage2014-09-25CandidatePoC-in-GitHub · ariarijp/vagrant-shellshockCVE-2014-6271の検証用Vagrantfileです★ 0ariarijp2014-09-25CandidatePoC-in-GitHub · themson/shellshockscripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271★ 1themson2014-09-25CandidatePoC-in-GitHub · securusglobal/BadBashCVE-2014-6271 (ShellShock) RCE PoC tool★ 4securusglobal2014-09-26CandidatePoC-in-GitHub · villadora/CVE-2014-6271scaner for cve-2014-6271★ 0villadora2014-09-26CandidatePoC-in-GitHub · APSL/salt-shellshockSalt recipe for shellshock (CVE-2014-6271)★ 1APSL2014-09-26CandidatePoC-in-GitHub · teedeedubya/bash-fix-exploitAnsible role to check the CVE-2014-6271 vulnerability★ 0teedeedubya2014-09-26CandidatePoC-in-GitHub · internero/debian-lenny-bash_3.2.52-cve-2014-6271Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)★ 0internero2014-09-26CandidatePoC-in-GitHub · u20024804/bash-3.2-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · u20024804/bash-4.2-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · u20024804/bash-4.3-fixed-CVE-2014-6271★ 0u200248042014-09-27CandidatePoC-in-GitHub · francisck/shellshock-cgiA python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server★ 12francisck2014-09-28CandidatePoC-in-GitHub · proclnas/ShellShock-CGI-ScanA script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)★ 1proclnas2014-09-28CandidatePoC-in-GitHub · sch3m4/RISCVE-2014-6271 Remote Interactive Shell - PoC Exploit★ 2sch3m42014-09-29CandidatePoC-in-GitHub · ryeyao/CVE-2014-6271_Test★ 1ryeyao2014-09-29CandidatePoC-in-GitHub · cj1324/CGIShellshellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI★ 13cj13242014-09-29CandidatePoC-in-GitHub · renanvicente/puppet-shellshockThis module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible★ 0renanvicente2014-09-29CandidatePoC-in-GitHub · indiandragon/Shellshock-Vulnerability-ScanAndroid app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock★ 11indiandragon2014-10-03CandidatePoC-in-GitHub · ramnes/pyshellshock:scream: Python library and utility for CVE-2014-6271 (aka. "shellshock")★ 2ramnes2014-11-06CandidatePoC-in-GitHub · akiraaisha/shellshocker-pythonThis is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271★ 3akiraaisha2015-02-22CandidatePoC-in-GitHub · 352926/shellshock_crawlerUsing google to scan sites for "ShellShock" (CVE-2014-6271)★ 03529262015-03-20CandidatePoC-in-GitHub · kelleykong/cve-2014-6271-mengjia-kongsystem reading course★ 0kelleykong2015-06-06CandidatePoC-in-GitHub · huanlu/cve-2014-6271-huan-lureading course★ 0huanlu2015-06-10CandidatePoC-in-GitHub · sunnyjiang/shellshocker-androidThis is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271★ 1sunnyjiang2015-06-17CandidatePoC-in-GitHub · P0cL4bs/ShellShock-CGI-ScanA script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).★ 6P0cL4bs2015-06-26CandidatePoC-in-GitHub · hmlio/vaas-cve-2014-6271Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock★ 22hmlio2015-07-11CandidatePoC-in-GitHub · opsxcq/exploit-CVE-2014-6271Shellshock exploit + vulnerable environment★ 232opsxcq2016-12-07CandidatePoC-in-GitHub · Pilou-Pilou/docker_CVE-2014-6271.★ 0Pilou-Pilou2017-01-25CandidatePoC-in-GitHub · zalalov/CVE-2014-6271Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell★ 4zalalov2017-04-30CandidatePoC-in-GitHub · heikipikker/shellshock-shellA simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.★ 0heikipikker2017-10-17CandidatePoC-in-GitHub · 0x00-0x00/CVE-2014-6271Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.★ 30x00-0x002017-11-23CandidatePoC-in-GitHub · kowshik-sundararajan/CVE-2014-6271CS4238 Computer Security Practices★ 0kowshik-sundararajan2018-05-05CandidatePoC-in-GitHub · w4fz5uck5/ShockZaum-CVE-2014-6271Shellshock vulnerability attacker★ 0w4fz5uck52018-06-18CandidatePoC-in-GitHub · Aruthw/CVE-2014-6271★ 0Aruthw2018-06-30CandidatePoC-in-GitHub · cved-sources/cve-2014-6271cve-2014-6271★ 0cved-sources2019-01-06CandidatePoC-in-GitHub · shawntns/exploit-CVE-2014-6271★ 0shawntns2019-04-27CandidatePoC-in-GitHub · Sindadziy/cve-2014-6271★ 0Sindadziy2019-11-12CandidatePoC-in-GitHub · wenyu1999/bash-shellshockcve-2014-6271★ 0wenyu19992019-11-13CandidatePoC-in-GitHub · Sindayifu/CVE-2019-14287-CVE-2014-6271★ 0Sindayifu2019-11-13CandidatePoC-in-GitHub · Any3ite/CVE-2014-6271★ 1Any3ite2020-01-06CandidatePoC-in-GitHub · somhm-solutions/Shell-Shock*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---★ 1somhm-solutions2020-01-28CandidatePoC-in-GitHub · rashmikadileeshara/CVE-2014-6271-Shellshock-This is an individual assignment for secure network programming★ 0rashmikadileeshara2020-05-12CandidatePoC-in-GitHub · Dilith006/CVE-2014-6271★ 0Dilith0062020-05-12CandidatePoC-in-GitHub · cyberharsh/Shellbash-CVE-2014-6271★ 0cyberharsh2020-06-26CandidatePoC-in-GitHub · MuirlandOracle/CVE-2014-6271-IPFire★ 0MuirlandOracle2020-11-12CandidatePoC-in-GitHub · mochizuki875/CVE-2014-6271-Apache-DebianThis Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).★ 1mochizuki8752021-07-24CandidatePoC-in-GitHub · b4keSn4ke/CVE-2014-6271Shellshock exploit aka CVE-2014-6271★ 15b4keSn4ke2021-07-29CandidatePoC-in-GitHub · akr3ch/CVE-2014-6271ShellShock interactive-shell exploit★ 4akr3ch2022-04-02CandidatePoC-in-GitHub · Gurguii/cgi-bin-shellshock[Python/Shell] - Tested in HackTheBox - Shocker (Easy) CVE-2014-6271★ 1Gurguii2022-06-23CandidatePoC-in-GitHub · anujbhan/shellshock-victim-hostA docker container vulnerable to Shellshock - CVE-2014-6271★ 0anujbhan2022-06-27CandidatePoC-in-GitHub · FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing★ 0FilipStudeny2022-09-09CandidatePoC-in-GitHub · mritunjay-k/CVE-2014-6271★ 0mritunjay-k2023-03-02CandidatePoC-in-GitHub · Brandaoo/CVE-2014-6271★ 0Brandaoo2023-03-25CandidatePoC-in-GitHub · J0hnTh3Kn1ght/CVE-2014-6271Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi★ 5J0hnTh3Kn1ght2023-07-01CandidatePoC-in-GitHub · hanmin0512/CVE-2014-6271_pwnable★ 0hanmin05122023-08-29CandidatePoC-in-GitHub · 0xN7y/CVE-2014-6271EXPLOIT FOR CVE-2014-6271★ 10xN7y2023-10-31CandidatePoC-in-GitHub · AlissonFaoli/ShellshockShellshock exploit (CVE-2014-6271)★ 0AlissonFaoli2024-02-04CandidatePoC-in-GitHub · ajansha/shellshockShelly is a lightweight and efficient vulnerability scanner designed to identify and mitigate Shellshock (CVE-2014-6271 & CVE-2014-7169) vulnerabilities in Bash environments.★ 0ajansha2024-05-10CandidatePoC-in-GitHub · K3ysTr0K3R/CVE-2014-6271-EXPLOITA PoC exploit for CVE-2014-6271 - Shellshock★ 4K3ysTr0K3R2024-05-18CandidatePoC-in-GitHub · TheRealCiscoo/shellshock-pocPrueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).★ 1TheRealCiscoo2024-07-14CandidatePoC-in-GitHub · RadYio/CVE-2014-6271Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible★ 1RadYio2024-11-26CandidatePoC-in-GitHub · YunchoHang/CVE-2014-6271-SHELLSHOCKAutomation script to exploit the Shellshock vulnerability.★ 0YunchoHang2025-02-26CandidatePoC-in-GitHub · moften/CVE-2014-6271Shellshock Vulnerability Scanner★ 0moften2025-05-05CandidatePoC-in-GitHub · knightc0de/Shellshock_vuln_ExploitCVE-2014-6271(RCE) poc Exploit★ 0knightc0de2025-06-14CandidatePoC-in-GitHub · rsherstnev/CVE-2014-6271This is my implementation of shellshock exploit★ 0rsherstnev2025-07-25CandidatePoC-in-GitHub · RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis★ 0RAJMadhusankha2025-08-09CandidatePoC-in-GitHub · DrHaitham/CVE-2014-6271-Shellshock-A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.★ 0DrHaitham2025-12-05CandidatePoC-in-GitHub · mtaha-sec/bash-apocalypseRecreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite methodology + Docker lab. Built for security research & education. Offensive security portfolio project.★ 0mtaha-sec2025-12-06CandidatePoC-in-GitHub · andres101c/Shellshock-CVE-2014-6271★ 0andres101c2026-02-17CandidatePoC-in-GitHub · Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-ShellshockCVE-2014-6271 Exploit | by infrar3d★ 0Industri4l-H3ll-Xpl0it3rs2026-02-19CandidatePoC-in-GitHub · 0xBlackash/CVE-2014-6271CVE-2014-6271★ 00xBlackash2026-03-06CandidatePoC-in-GitHub · ambjlou/it355-lab4-enterprise-lan-securityThis repository contains a comprehensive security assessment of an enterprise LAN environment. The core focus of this project was the identification, exploitation, and remediation of the **Shellshock (CVE-2014-6271)** vulnerability within a Linux-based web server.★ 0ambjlou2026-04-02CandidatePoC-in-GitHub · kaleth4/-CVE-2014-6271★ 0kaleth42026-04-09CandidatePoC-in-GitHub · kaleth4/CVE-2014-6271★ 0kaleth42026-04-09CandidatePoC-in-GitHub · V3nG4mxV1p3r/Mobile-Drop-Device-SOC-DetectionEnd-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).★ 1V3nG4mxV1p3r2026-04-22CandidatePoC-in-GitHub · im2sinister/CVE-2014-6271its simple Shellshock exploit★ 1im2sinister2026-04-24CandidatePoC-in-GitHub · HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-ThorBlack-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.★ 0HevenTafese2026-04-30CandidatePoC-in-GitHub · FacundoMfernandez/pentesting-obiobaPentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico★ 0FacundoMfernandez2026-05-05CandidatePoC-in-GitHub · R3fr4kt/Shocker-TJNULL-OSCP-"A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors."★ 0R3fr4kt2026-06-02CandidatePoC-in-GitHub · cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-ReportThis repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.★ 0cyberexpert1112026-07-05CandidatePoC-in-GitHub · caverm/Shellshock_CVE-2014-6271Shellshock★ 0caverm2026-07-07CandidatePoC-in-GitHub · FREEGUY-6/dmz-security-monitoring-hardeningCY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271★ 1FREEGUY-62026-08-03CandidatePoC-in-GitHub · Vaibhav91one/shellshock-cve-labShellshock CVE-2014-6271 vulnerable CGI lab★ 0Vaibhav91one2026-08-30Candidate