Impact
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.7 suffers from a denial of service vulnerability that allows a remote attacker to send a specially crafted request that forces the server to consume excessive memory resources. The flaw is classified as a resource consumption weakness (CWE‑770).
Affected Systems
The affected operating environment is IBM WebSphere Application Server Liberty, versions 17.0.0.3 up to 26.0.0.7, which may include the servlet-3.1, servlet-4.0, servlet-5.0, servlet-6.0, or servlet-6.1 features.
Risk and Exploitability
The vulnerability scores a CVSS of 7.5, indicating a high severity. The EPSS score is < 1%, suggesting a very low exploitation probability. The issue is not listed in the CISA KEV catalog. The likely attack vector is remote, through a crafted HTTP/2 request sent over the network to the WebSphere Application Server Liberty instance. Successful exploitation would lead to memory exhaustion and service disruption for legitimate users.
OpenCVE Enrichment