critical
CVE-2017-5638
Struts Jakarta multipart parser OGNL injection - unauthenticated RCE via the Content-Type header (Equifax)
- Severity
- critical
- Affected product
- Apache Struts
- Affected versions
- Apache Struts ≥ 2.3.0, < 2.3.32
- Affected versions
- Apache Struts ≥ 2.5.0, < 2.5.10.1
- Fixed in
- Apache Struts 2.3.32
- Fixed in
- Apache Struts 2.5.10.1
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Apache Struts from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Apache Struts from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →