← All CVEs NewScan detects
critical

CVE-2017-5638

Struts Jakarta multipart parser OGNL injection - unauthenticated RCE via the Content-Type header (Equifax)

Severity
critical
Affected product
Apache Struts
Affected versions
Apache Struts ≥ 2.3.0, < 2.3.32
Affected versions
Apache Struts ≥ 2.5.0, < 2.5.10.1
Fixed in
Apache Struts 2.3.32
Fixed in
Apache Struts 2.5.10.1
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Apache Struts from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

COMPONENT VERSION RANGE

NewScan fingerprints Apache Struts from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →