OGNL injection decoder
Paste an OGNL payload you found in a WAF or application log and read what it was trying to do. Separates a sandbox escape from an execution call, names the advisory family the shape is consistent with, and always states what it did not determine. Decodes only - it never evaluates the payload and holds no templates.
Security & WAFRead locally in your browser. Nothing is sent anywhere, and nothing in the payload is evaluated — the tool recognises syntax and describes it.
References
- Apache Struts security bulletin S2-045 (CVE-2017-5638): remote code execution via the Jakarta multipart parser
- Apache Struts security bulletin S2-057 (CVE-2018-11776): possible RCE when namespace and result values are evaluated
- Apache Commons OGNL language guide: expression syntax and static method access