← Vulnerability feed

Vulnerability record · CVE-2016-9606 · published 9 March 2018

CVE-2016-9606: Redhat resteasy improper input validation vulnerability

Redhat · Resteasy

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

8.1 CVSS 3.0 High EPSS 6.0% · top 7.0% CWE-20 · Improper input validation
8.1CVSS 3.0 base score, v2 6.8
6.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
17 Jun 2026Last modified by NVD

Description

JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2017-1255.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-1409.html Third Party Advisory
http://www.securityfocus.com/bid/94940 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038524 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:1253 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1254 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1256 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1260 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1410 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1411 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1412 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1675 Broken LinkThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1676 Broken LinkThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:2909
https://access.redhat.com/errata/RHSA-2018:2913
https://bugzilla.redhat.com/show_bug.cgi?id=1400644 Issue TrackingThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-1255.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-1409.html Third Party Advisory
http://www.securityfocus.com/bid/94940 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1038524 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:1253 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1254 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1256 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1260 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1410 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1411 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1412 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1675 Broken LinkThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1676 Broken LinkThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:2909
https://access.redhat.com/errata/RHSA-2018:2913
https://bugzilla.redhat.com/show_bug.cgi?id=1400644 Issue TrackingThird Party Advisory

Track CVE-2016-9606 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2018-1051Redhat resteasy improper input validation vulnerabilityIt was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Resteasy is still possible via `Yam…EPSS 1.3%7.5CVE-2020-14326Redhat integration camel k uncontrolled resource consumption vulnerabilityA vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…EPSS 1.2%7.5CVE-2020-1695Redhat resteasy improper input validation vulnerabilityA flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…EPSS 2.0%7.5CVE-2016-6346Redhat resteasy vulnerabilityRESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.EPSS 5.6%7.5CVE-2014-3490Redhat jboss enterprise application platform vulnerabilityRESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external…EPSS 4.6%6.5CVE-2016-6345Redhat resteasy information exposure vulnerabilityRESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.EPSS 1.8%6.4CVE-2014-7839Redhat resteasy improper input validation vulnerabilityDocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which …EPSS 2.0%6.1CVE-2021-20293Redhat resteasy cross-site scripting vulnerabilityA reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2016-9606), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.