Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2025-10-02 — agencies required to remediate by 2025-10-23

CVE-2014-6278

Published
Sep 30, 2014
Updated
Apr 16, 2026
Affected
0 pkgs
Patched
None yet
Exploits
8 known

EPSS Exploitation Probability

via FIRST.org ↗
91.7%probability of exploitation in next 30 days
Very High Risk100th percentile0.00%
89.4%90.3%91.3%92.2%89.9%91.7%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

Exploits & PoCs
8

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-39887webappscgi

Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)

by lastc0de · Jun 6, 2016

EDB-39568remotehardware

Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)

by thatchriseckert · Mar 16, 2016

EDB-34860remotelinux

GNU bash 4.3.11 - Environment Variable dhclient

by @0x00string · Oct 2, 2014

EDB-36933remotelinux✓ Verified

dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)

by fdiskyou · Sep 29, 2014

EDB-34900remotelinux✓ Verified

Apache mod_cgi - 'Shellshock' Remote Command Injection

by Federico Galatolo · Oct 6, 2014

Frequently Asked Questions

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and C
O3 Security · Impact-Aware SCA

Is CVE-2014-6278 in your stack?

O3 detects CVE-2014-6278 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.