← Vulnerability feed

Vulnerability record · CVE-2017-9805 · published 15 September 2017

CVE-2017-9805: Apache Struts REST Plugin XStream deserialization RCE

Apache · Struts

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deserialization without type filtering. Deserializing attacker-supplied XML payloads can therefore lead to remote code execution. This is a well-known, actively exploited flaw with a very high EPSS score.

8.1 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 99% · top 0.1% CWE-502 · Deserialization of untrusted data
8.1CVSS 3.1 base score, v2 6.8
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
7Affected product versions listed by NVD
25References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-maximum EPSS score and public exploit code, and it enables unauthenticated remote code execution.

What it is

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an XStream instance for deserialization without type filtering. Deserializing attacker-supplied XML payloads can therefore lead to remote code execution. This is a well-known, actively exploited flaw with a very high EPSS score.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the Struts application, leading to full server compromise. This can result in data theft, persistence, and lateral movement.

Attack surface

Reachable over the network via HTTP requests to Struts REST endpoints that deserialize XML, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CVE-2017-9805 is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99396 (99.94th percentile). A public Exploit-DB entry (42627) exists, confirming weaponized exploit code is available.

What to do

  • Upgrade Apache Struts to 2.3.34 or 2.5.13 or later as directed by the vendor advisory (S2-052).
  • Apply vendor patches for affected third-party products (Cisco, NetApp, Oracle) that bundle Struts.
  • If immediate upgrade is not possible, disable or restrict the Struts REST plugin and avoid XML deserialization endpoints.
  • Follow the S2-052 mitigation guidance to remove or replace the XStreamHandler where feasible.
  • Monitor for and block exploit attempts targeting REST endpoints with XML content types.

Detection

  • Inspect HTTP requests to Struts REST endpoints for XML bodies containing XStream-style class references or unusual serialized objects.
  • Monitor application and web server logs for errors or stack traces related to XStream deserialization.
  • Use network IDS/IPS signatures for known CVE-2017-9805 exploit patterns and the public Exploit-DB PoC.
  • Alert on unexpected child processes or outbound connections originating from the Java/Struts application server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-9805 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache Struts Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html PatchThird Party Advisory
http://www.securityfocus.com/bid/100609 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039263 Broken LinkThird Party AdvisoryVDB Entry
https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1488482 Issue TrackingThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/WW/S2-052 MitigationVendor Advisory
https://lgtm.com/blog/apache_struts_CVE-2017-9805 Broken Link
https://security.netapp.com/advisory/ntap-20170907-0001/ Third Party Advisory
https://struts.apache.org/docs/s2-052.html MitigationVendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2 Third Party Advisory
https://www.exploit-db.com/exploits/42627/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/112992 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html PatchThird Party Advisory
http://www.securityfocus.com/bid/100609 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039263 Broken LinkThird Party AdvisoryVDB Entry
https://blogs.apache.org/foundation/entry/apache-struts-statement-on-equifax Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1488482 Issue TrackingThird Party AdvisoryVDB Entry
https://cwiki.apache.org/confluence/display/WW/S2-052 MitigationVendor Advisory
https://lgtm.com/blog/apache_struts_CVE-2017-9805 Broken Link
https://security.netapp.com/advisory/ntap-20170907-0001/ Third Party Advisory
https://struts.apache.org/docs/s2-052.html MitigationVendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2 Third Party Advisory
https://www.exploit-db.com/exploits/42627/ ExploitThird Party AdvisoryVDB Entry
https://www.kb.cert.org/vuls/id/112992 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9805 US Government Resource

Track CVE-2017-9805 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2017-9791Apache Struts 1 plugin input validation flaw enables remote code executionThe Struts 1 plugin in Apache Struts 2.1.x and 2.3.x may allow remote code execution when a malicious field value is passed in a raw message to the A…KEVEPSS 99%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed9.8CVE-2013-2251Apache Struts 2 OGNL injection enables remote code executionApache Struts 2.0.0 through 2.3.15 fails to properly validate request parameters, allowing crafted action:, redirect:, or redirectAction: prefixes to…KEVEPSS 100%analysed9.8CVE-2012-0391Apache Struts ExceptionDelegator OGNL injection enables remote code executionApache Struts before 2.2.3.1 evaluates parameter values as OGNL expressions in the ExceptionDelegator component during exception handling for mismatc…KEVEPSS 76%analysed8.1CVE-2018-11776Apache Struts namespace handling flaw enables remote code executionApache Struts 2.3 through 2.3.34 and 2.5 through 2.5.16 can execute remote code when alwaysSelectFullNamespace is enabled and results or url tags are…KEVEPSS 100%analysed7.5CVE-2006-1547Apache Struts 1 ActionForm multipart parameter denial of serviceApache Struts before 1.2.9 with BeanUtils 1.7 exposes the public getMultipartRequestHandler method through ActionForm parameter binding. A remote att…KEVEPSS 55%analysed10.0CVE-2013-4316Apache struts improper access control vulnerabilityApache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.EPSS 8.4%

Source: NIST National Vulnerability Database (record CVE-2017-9805), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.