CVE-2016-9596: Red Hat JBoss Core Services

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-3627.

Affected products

  • Red Hat JBoss Core Services: affected versions not specified
  • Xmlsoft LIBXML2: before 2.9.4 (fixed in 2.9.4)

Published 2018-08-16. Last modified 2026-06-17.