← Global Threat Landscape

CVE-2017-9805

CWE-502

Critical

93.6

RPS

Description

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

Source: NVD

Signals

CVSS
8.1
High · v3.1
EPSS
99.39%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Nov 2021
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-502
Published
15 Sept 2017
Last modified 21 Apr 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2017-9805

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2017-9805 · RPS 93.6 · DevSecure Intelligence