OGNL injection decoder

Paste an OGNL payload you found in a WAF or application log and read what it was trying to do. Separates a sandbox escape from an execution call, names the advisory family the shape is consistent with, and always states what it did not determine. Decodes only - it never evaluates the payload and holds no templates.

Security & WAF

Read locally in your browser. Nothing is sent anywhere, and nothing in the payload is evaluated — the tool recognises syntax and describes it.

References