CVE-2017-5638
KEV RANSOMWARECRITICAL 10.0EPSS 100.0%
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 10.0 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-20
- Published
- 2017-03-11
- Updated
- 2025-10-21
Proof-of-concept exploits (113)
- http://blog.talosintelligence.com/2017/03/apache-0-day-exploited.html
- http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-5638-apache-struts-vu…
- https://isc.sans.edu/diary/22169
- https://packetstormsecurity.com/files/141494/S2-45-poc.py.txt
- https://exploit-db.com/exploits/41570
- 0pensrcerer/struts2-rce-public0★ · 2021-07-21
- 0pensrcerer/struts2rce0★ · 2022-02-22
- 0x00-0x00/CVE-2017-56386★ · 2018-02-15
- Badbird3/CVE-2017-56380★ · 2021-06-24
- FredBrave/CVE-2017-5638-ApacheStruts2.3.50★ · 2023-05-10
- Greynad/struts2-jakarta-inject2★ · 2018-03-19
- Iletee/struts2-rce11★ · 2026-04-15
- JShortSona/Jenkins-Struts20★ · 2023-04-12
- Jodagh/struts0★ · 2023-12-11
- Kaizhe/attacker1★ · 2021-01-04
- KarzsGHR/S2-046_S2-045_POC1★ · 2017-04-26
- MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION0★ · 2025-09-06
- NAIRBS/SC3010-Grp-330★ · 2025-04-08
- PranjalBugged-Out/Equifax-Data-Breach-Educational-Video0★ · 2025-08-15
- QHxDr-dz/CVE-2017-56380★ · 2025-07-27
- R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-3★ · 2017-07-24
- SpiderMate/Stutsfi0★ · 2018-01-13
- Tankirat/CVE-2017-56380★ · 2022-03-28
- TheTechSurgeon/struts2-rce-public0★ · 2021-07-21
- TheTechSurgeon/struts2rce0★ · 2022-02-22
- Xernary/CVE-2017-5638-POC1★ · 2025-02-06
- Xhendos/CVE-2017-56380★ · 2017-08-26
- abaer123/BaerBox-Struts2-RCE0★ · 2022-01-21
- acpcreation/Github-SCA0★ · 2025-06-23
- aljazceru/CVE-2017-5638-Apache-Struts22★ · 2017-03-11
- amitnandi04/Common-Vulnerability-Exposure-CVE-0★ · 2020-10-14
- bongbongco/cve-2017-56380★ · 2017-03-08
- c002/Apache-Struts0★ · 2017-05-28
- c1apps/c1-apache-struts20★ · 2022-05-06
- cafnet/apache-struts-v2-CVE-2017-56380★ · 2018-01-28
- chanamoallim/Apache-Struts-Exploit-with-Metasploit0★ · 2025-08-01
- code-sharx/struts2-rce0★ · 2025-07-28
- colorblindpentester/CVE-2017-56380★ · 2019-03-22
- cx-benjamin-simpson/struts2-rce-public0★ · 2021-07-21
- cx-benjamin-simpson/struts2rce0★ · 2022-02-22
- delanAtMergebase/defender-demo0★ · 2024-05-28
- donaldashdown/Common-Vulnerability-and-Exploit0★ · 2017-11-11
- eannaratone/struts2-rce0★ · 2022-05-16
- eeehit/CVE-2017-56380★ · 2017-06-13
- f5oto/hackable0★ · 2021-11-12
- falcon-lnhg/StrutsShell3★ · 2017-04-04
- haxerr9/CVE-2017-56381★ · 2025-06-08
- haydena23/NSESearch6★ · 2025-09-17
- homjxi0e/CVE-2017-56380★ · 2017-06-08
- hook-s3c/CVE-2018-11776-Python-PoC123★ · 2018-08-25
- iampetru/PoC-CVE-2017-56383★ · 2025-08-25
- immunio/apache-struts2-CVE-2017-563835★ · 2017-03-13
- initconf/CVE-2017-5638_struts8★ · 2017-09-15
- injcristianrojas/cve-2017-56380★ · 2022-04-22
- izapps/c1-apache-struts20★ · 2022-05-06
- jas502n/S2-045-EXP-POC-TOOLS25★ · 2021-08-18
- jas502n/st2-046-poc21★ · 2018-08-17
- java-benchmark/struts2-showcase0★ · 2022-09-29
- jnicastro-Sonatype/struts2-rce-github-flo-public0★ · 2021-08-25
- jongmartinez/CVE-2017-56381★ · 2020-12-06
- jorgevillaescusa/c1-apache-struts20★ · 2021-03-16
- jpacora/Struts2Shell1★ · 2017-06-03
- jptr218/struts_hack1★ · 2021-08-20
- jrrdev/cve-2017-563814★ · 2017-04-04
- jrrombaldo/CVE-2017-56380★ · 2024-03-29
- kloutkake/CVE-2017-5638-PoC2★ · 2024-09-12
- leandrocamposcardoso/CVE-2017-5638-Mass-Exploit0★ · 2020-06-07
- lolwaleet/ExpStruts2★ · 2017-03-12
- m3ssap0/struts2_cve-2017-56381★ · 2018-03-10
- maurycupitt/struts2-rce-github-mc0★ · 2025-08-07
- mazen160/struts-pwn442★ · 2018-05-21
- mcassano/cve-2017-56380★ · 2017-04-01
- mfdev-solution/Exploit-CVE-2017-56380★ · 2022-12-21
- mike-williams/Struts2Vuln1★ · 2017-09-15
- mritunjay-k/CVE-2017-56380★ · 2023-03-02
- norsemen-local/lambdalabs2★ · 2026-03-19
- octodemo/Moose-Dependabot-Twitch3★ · 2023-12-07
- oktavianto/CVE-2017-5638-Apache-Struts21★ · 2017-03-20
- paralelo14/CVE_2017_56381★ · 2017-03-14
- payatu/CVE-2017-56388★ · 2017-05-05
- pr0x1ma-byte/cybersecurity-struts21★ · 2019-01-23
- praveenmv-git/dependabotdemo0★ · 2024-11-21
- random-robbie/CVE-2017-56380★ · 2017-03-16
- readloud/CVE-2017-56380★ · 2022-02-28
- riyazwalikar/struts-rce-cve-2017-56381★ · 2017-06-08
- sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-563813★ · 2017-06-30
- samqbush/struts2-showcase1★ · 2022-07-08
- samuelproject/ApacheStruts20★ · 2017-03-13
- sealmindset/struts2rce0★ · 2025-01-25
- secretmike/demo-app1★ · 2021-11-22
- seeewhy/sonatype-nexus-community0★ · 2021-12-02
- sighup1/cybersecurity-struts21★ · 2019-01-23
- sjitech/test_struts2_vulnerability_CVE-2017-56380★ · 2017-03-13
- sn-ravance/struts2-rce0★ · 2022-09-30
- sonatype-workshops/struts2-rce0★ · 2022-08-18
- sonatype/sonatype-field-workshop0★ · 2024-12-23
- sotudeko/struts2-rce0★ · 2020-11-26
- ss9214/cs564capstone0★ · 2025-05-11
- stnert/cybersec-pwn-pres0★ · 2024-01-26
- tahmed11/strutsy10★ · 2018-09-01
- tomgranados/struts-rce0★ · 2019-11-28
- toothbrushsoapflannelbiscuits/cve-2017-56380★ · 2025-05-09
- tsheth/JavaStruts-App-Terraform0★ · 2018-06-23
- un4ckn0wl3z/CVE-2017-56381★ · 2018-11-22
- wangeradd1/MyPyExploit4★ · 2017-05-17
- win3zz/CVE-2017-563816★ · 2018-05-13
- xeroxis-xs/Computer-Security-Apache-Struts-Vulnerability0★ · 2024-04-22
- xsscx/cve-2017-563822★ · 2017-03-12
- zacharie410/Exploiting-Web-Apps3★ · 2023-04-03
- AIPEACS/SC3010-Computer-Security
- Dungsocool/CVE-2017-5638
- smancke/CVE-2017-5638
- btamburi/strutszeiro