What happened
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Affected versions
Struts: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 41570Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code ExecutionVex Woo2017-03-07VerifiedExploit-DB 41614Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)Metasploit2017-03-15VerifiedPoC-in-GitHub · PolarisLab/S2-045Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html★ 23PolarisLab2017-03-07CandidatePoC-in-GitHub · Flyteas/Struts2-045-ExpStruts2 S2-045(CVE-2017-5638)Exp with GUI★ 61Flyteas2017-03-07CandidatePoC-in-GitHub · bongbongco/cve-2017-5638★ 0bongbongco2017-03-08CandidatePoC-in-GitHub · jas502n/S2-045-EXP-POC-TOOLSS2-045 漏洞 POC-TOOLS CVE-2017-5638★ 25jas502n2017-03-09CandidatePoC-in-GitHub · btamburi/strutszeiroTelegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)★ 0btamburi2017-03-10CandidatePoC-in-GitHub · xsscx/cve-2017-5638Example PoC Code for CVE-2017-5638 | Apache Struts Exploit★ 22xsscx2017-03-10CandidatePoC-in-GitHub · immunio/apache-struts2-CVE-2017-5638Demo Application and Exploit★ 35immunio2017-03-10CandidatePoC-in-GitHub · Masahiro-Yamada/OgnlContentTypeRejectorValveThis is Valve for Tomcat7 to block Struts 2 Remote Code Execution vulnerability (CVE-2017-5638)★ 1Masahiro-Yamada2017-03-11CandidatePoC-in-GitHub · aljazceru/CVE-2017-5638-Apache-Struts2Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates★ 2aljazceru2017-03-11CandidatePoC-in-GitHub · sjitech/test_struts2_vulnerability_CVE-2017-5638test struts2 vulnerability CVE-2017-5638 in Mac OS X★ 0sjitech2017-03-11CandidatePoC-in-GitHub · jrrombaldo/CVE-2017-5638★ 0jrrombaldo2017-03-11CandidatePoC-in-GitHub · random-robbie/CVE-2017-5638CVE: 2017-5638 in different formats★ 0random-robbie2017-03-11CandidatePoC-in-GitHub · initconf/CVE-2017-5638_strutsdetection for Apache Struts recon and compromise★ 8initconf2017-03-11CandidatePoC-in-GitHub · mazen160/struts-pwnAn exploit for Apache Struts CVE-2017-5638★ 442mazen1602017-03-12CandidatePoC-in-GitHub · ret2jazzy/Struts-Apache-ExploitPackThese are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)★ 16ret2jazzy2017-03-12CandidatePoC-in-GitHub · lolwaleet/ExpStrutsA php based exploiter for CVE-2017-5638.★ 2lolwaleet2017-03-12CandidatePoC-in-GitHub · oktavianto/CVE-2017-5638-Apache-Struts2Example PHP Exploiter for CVE-2017-5638★ 1oktavianto2017-03-13CandidatePoC-in-GitHub · jrrdev/cve-2017-5638cve-2017-5638 Vulnerable site sample★ 14jrrdev2017-03-15CandidatePoC-in-GitHub · opt9/StrutshockStruts2 RCE CVE-2017-5638 non-intrusive check shell script★ 2opt92017-03-16CandidatePoC-in-GitHub · falcon-lnhg/StrutsShellApache Struts (CVE-2017-5638) Shell★ 3falcon-lnhg2017-03-17CandidatePoC-in-GitHub · jas502n/st2-046-pocst2-046-poc CVE-2017-5638★ 21jas502n2017-03-21CandidatePoC-in-GitHub · KarzsGHR/S2-046_S2-045_POCS2-046|S2-045: Struts 2 Remote Code Execution vulnerability(CVE-2017-5638)★ 1KarzsGHR2017-03-21CandidatePoC-in-GitHub · gsfish/S2-ReaperCVE-2017-5638★ 0gsfish2017-03-23CandidatePoC-in-GitHub · mcassano/cve-2017-5638★ 0mcassano2017-03-26CandidatePoC-in-GitHub · opt9/StrutscliStruts2 RCE CVE-2017-5638 CLI shell★ 2opt92017-03-28CandidatePoC-in-GitHub · tahmed11/strutsyStrutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability★ 10tahmed112017-04-09CandidatePoC-in-GitHub · payatu/CVE-2017-5638Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header★ 8payatu2017-05-05CandidatePoC-in-GitHub · Aasron/Struts2-045-ExpCVE-2017-5638★ 0Aasron2017-05-27CandidatePoC-in-GitHub · SpiderMate/StutsfiAn exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2★ 0SpiderMate2017-05-28CandidatePoC-in-GitHub · jpacora/Struts2ShellAn exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.★ 1jpacora2017-05-28CandidatePoC-in-GitHub · smancke/CVE-2017-5638★ 0smancke2017-06-07CandidatePoC-in-GitHub · riyazwalikar/struts-rce-cve-2017-5638Struts-RCE CVE-2017-5638★ 1riyazwalikar2017-06-08CandidatePoC-in-GitHub · homjxi0e/CVE-2017-5638★ 0homjxi0e2017-06-08CandidatePoC-in-GitHub · eeehit/CVE-2017-5638CVE-2017-5638 Test environment★ 0eeehit2017-06-13CandidatePoC-in-GitHub · sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner★ 0sUbc0ol2017-06-30CandidatePoC-in-GitHub · sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638★ 13sUbc0ol2017-06-30CandidatePoC-in-GitHub · R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-Exploit created by: R4v3nBl4ck end Pacman★ 3R4v3nBl4ck2017-07-24CandidatePoC-in-GitHub · Xhendos/CVE-2017-5638★ 0Xhendos2017-08-12CandidatePoC-in-GitHub · invisiblethreat/strutserCheck for Struts Vulnerability CVE-2017-5638★ 0invisiblethreat2017-09-25CandidatePoC-in-GitHub · c002/Apache-StrutsAn exploit for Apache Struts CVE-2017-5638★ 0c0022017-10-19CandidatePoC-in-GitHub · donaldashdown/Common-Vulnerability-and-ExploitThis is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.★ 0donaldashdown2017-10-30CandidatePoC-in-GitHub · sighup1/cybersecurity-struts2Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.★ 1sighup12018-01-18CandidatePoC-in-GitHub · cafnet/apache-struts-v2-CVE-2017-5638Working POC for CVE 2017-5638★ 0cafnet2018-01-28CandidatePoC-in-GitHub · 0x00-0x00/CVE-2017-5638Struts02 s2-045 exploit program★ 60x00-0x002018-02-15CandidatePoC-in-GitHub · m3ssap0/struts2_cve-2017-5638This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.★ 1m3ssap02018-02-28CandidatePoC-in-GitHub · Greynad/struts2-jakarta-injectGolang exploit for CVE-2017-5638★ 2Greynad2018-03-14CandidatePoC-in-GitHub · ggolawski/struts-rceApache Struts CVE-2017-5638 RCE exploitation★ 1ggolawski2018-03-20CandidatePoC-in-GitHub · win3zz/CVE-2017-5638Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script★ 16win3zz2018-05-13CandidatePoC-in-GitHub · leandrocamposcardoso/CVE-2017-5638-Mass-Exploit★ 0leandrocamposcardoso2018-06-24CandidatePoC-in-GitHub · Iletee/struts2-rceExploitable target to CVE-2017-5638★ 11Iletee2018-06-26CandidatePoC-in-GitHub · andypitcher/check_strutsApache Struts version analyzer (Ansible) based on CVE-2017-5638★ 2andypitcher2018-09-04CandidatePoC-in-GitHub · un4ckn0wl3z/CVE-2017-5638★ 1un4ckn0wl3z2018-11-22CandidatePoC-in-GitHub · colorblindpentester/CVE-2017-5638CVE-2017-5638 (PoC Exploits)★ 0colorblindpentester2019-03-22CandidatePoC-in-GitHub · injcristianrojas/cve-2017-5638Demo app of THAT data broker's security breach★ 0injcristianrojas2019-08-15CandidatePoC-in-GitHub · ludy-dev/XworkStruts-RCE(CVE-2017-5638) XworkStruts RCE Vuln test script★ 1ludy-dev2020-08-31CandidatePoC-in-GitHub · sonatype-workshops/struts2-rceExploitable target to CVE-2017-5638★ 0sonatype-workshops2020-10-19CandidatePoC-in-GitHub · jongmartinez/CVE-2017-5638PoC for CVE: 2017-5638 - Apache Struts2 S2-045★ 1jongmartinez2020-12-06CandidatePoC-in-GitHub · Badbird3/CVE-2017-5638★ 0Badbird32021-06-24CandidatePoC-in-GitHub · jptr218/struts_hackAn implementation of CVE-2017-5638★ 1jptr2182021-08-04CandidatePoC-in-GitHub · testpilot031/vulnerability_struts-2.3.31Build the struts-2.3.31 (CVE-2017-5638) environment★ 0testpilot0312022-02-15CandidatePoC-in-GitHub · readloud/CVE-2017-5638This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.★ 0readloud2022-02-28CandidatePoC-in-GitHub · Tankirat/CVE-2017-5638★ 0Tankirat2022-03-28CandidatePoC-in-GitHub · mfdev-solution/Exploit-CVE-2017-5638this exemple of application permet to test the vunerability CVE_2017-5638★ 0mfdev-solution2022-12-21CandidatePoC-in-GitHub · mritunjay-k/CVE-2017-5638An exploit for CVE-2017-5638★ 0mritunjay-k2023-03-02CandidatePoC-in-GitHub · FredBrave/CVE-2017-5638-ApacheStruts2.3.5A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10★ 0FredBrave2023-05-10CandidatePoC-in-GitHub · Nithylesh/web-application-firewall-This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).★ 3Nithylesh2024-07-11CandidatePoC-in-GitHub · kloutkake/CVE-2017-5638-PoCThis repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.★ 2kloutkake2024-09-04CandidatePoC-in-GitHub · Xernary/CVE-2017-5638-POCProof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server★ 1Xernary2024-12-08CandidatePoC-in-GitHub · timothyjxhn/DeliberatelyVulnerableWebAppA Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.★ 0timothyjxhn2025-03-27CandidatePoC-in-GitHub · toothbrushsoapflannelbiscuits/cve-2017-5638★ 0toothbrushsoapflannelbiscuits2025-05-02CandidatePoC-in-GitHub · haxerr9/CVE-2017-5638CVE-2017-5638 Exploit Rewritten In Python By haxerr9★ 1haxerr92025-06-07CandidatePoC-in-GitHub · QHxDr-dz/CVE-2017-5638★ 0QHxDr-dz2025-07-27CandidatePoC-in-GitHub · joidiego/Detection-struts-cve-2017-5638-detectorReal-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.★ 0joidiego2025-07-30CandidatePoC-in-GitHub · iampetru/PoC-CVE-2017-5638Apache Struts2 CVE-2017-5638 (Safe Educational Demo)★ 3iampetru2025-08-25CandidatePoC-in-GitHub · MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION★ 0MuhammadAbdullah1922025-09-06CandidatePoC-in-GitHub · kaylertee/Computer-Security-Equifax-2017A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos★ 0kaylertee2025-09-11CandidatePoC-in-GitHub · ACharaf06/CVE-2017-5638-Attack-and-Defense★ 1ACharaf062025-12-15CandidatePoC-in-GitHub · soufiane-benchahyd/vulhub-struts2A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.★ 0soufiane-benchahyd2026-02-20CandidatePoC-in-GitHub · AIPEACS/SC3010-Computer-SecurityUsing Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.★ 0AIPEACS2026-04-05CandidatePoC-in-GitHub · Kouf320/docker-lab-cve-2017-5638-cve-2021-41773★ 2Kouf3202026-04-11CandidatePoC-in-GitHub · Majaktech/apache-struts-cve-2017-5638-projectAttack and Defense course project focused on CVE-2017-5638 analysis, exploitation, and mitigation.★ 0Majaktech2026-05-18CandidatePoC-in-GitHub · Dungsocool/CVE-2017-5638★ 0Dungsocool2026-05-26CandidatePoC-in-GitHub · GU-007/struts2-toolStruts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool★ 1GU-0072026-09-03CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.