Description
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
Published: 2026-07-28
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Request Smuggling
Action: Patch Now
AI Analysis

Impact

The latest description indicates a flaw that allows HTTP request smuggling in IBM WebSphere Application Server and its Liberty profile. Detailed specifics beyond the statement that the server may mis-handle request boundaries are not disclosed in the current data, but the impact remains that an attacker could manipulate crafted HTTP requests to bypass access controls, read or modify sensitive data, or disrupt service availability.

Affected Systems

Affected products include IBM WebSphere Application Server versions 8.5.0 through 8.5.5.30 and 9.0.0 through 9.0.5.28, as well as WebSphere Application Server Liberty releases 17.0.0.3 through 26.0.0.7 that support servlet specifications 3.0 to 6.1. The vulnerability applies only when the relevant servlet feature is enabled in these releases.

Risk and Exploitability

The CVSS score of 7.4 classifies this defect as high severity, while the EPSS score indicates a very low probability of exploitation (<1%). It is not listed in the CISA KEV catalog, suggesting no known active exploits at this time. The likely attack vector is network‑based, inferred because the vulnerability involves HTTP request smuggling which typically requires an attacker to send crafted requests over the network to a vulnerable WebSphere Application Server. Exploitation requires the target to have the susceptible servlet feature enabled and to receive the targeted HTTP traffic.

Generated by OpenCVE AI on September 23, 2026 at 22:40 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH72191 or PH72192. To determine if a feature is enabled for WebSphere Application Server Liberty, refer to  How to determine if Liberty is using a specific feature https://www.ibm.com/support/pages/node/6553910 .   For IBM WebSphere Application Server Liberty 17.0.0.3 - 26.0.0.7 using servlet-3.0, servlet-3.1, servlet-4.0, servlet-5.0, servlet-6.0, or servlet-6.1  feature(s): · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72191 https://www.ibm.com/support/pages/node/7277460 --OR-- · Apply Fix Pack 26.0.0.8 or later (targeted availability 3Q2026). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH72192 https://www.ibm.com/support/pages/node/7281143 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).   For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix that resolves PH72192 https://www.ibm.com/support/pages/node/7281143 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026). Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Upgrade to the minimum required fix pack level and apply IBM’s interim fix PH72191 for Liberty or PH72192 for traditional WebSphere Application Server, then update to the latest specified fix pack (Liberty 26.0.0.8 or newer, WebSphere 9.0.5.29 or 8.5.5.31) to fully resolve the issue.
  • Verify that the servlet‑related feature causing the smuggling is enabled in your deployment; disable or reconfigure it as appropriate following IBM’s guidance on feature determination.
  • Check IBM’s support pages for any additional interim fixes that may apply to your version and apply them promptly.

Generated by OpenCVE AI on September 23, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.

Wed, 29 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
Title IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
First Time appeared Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:17.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server___liberty:26.0.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
Ibm websphere Application Server Liberty
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Websphere Application Server Websphere Application Server Liberty
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T20:50:48.871Z

Reserved: 2026-07-09T18:20:49.634Z

Link: CVE-2026-15328

cve-icon Vulnrichment

Updated: 2026-07-29T14:03:41.027Z

cve-icon NVD

Status : Modified

Published: 2026-07-28T21:17:27.920

Modified: 2026-09-23T21:16:58.357

Link: CVE-2026-15328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T22:45:10Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')