Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cache poisoning and WAF bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper parsing of the HTTP transfer‑encoding header, allowing HTTP request smuggling. With a crafted request, WebSphere may treat multiple requests as one, leading to web cache poisoning, bypass of a Web Application Firewall, and enabling cross‑site scripting attacks. This weakness is categorized as CWE‑444.

Affected Systems

IBM WebSphere Application Server versions prior to 9.0.5.29 in the 9.0.x line and prior to 8.5.5.31 in the 8.5.x line are affected; the Liberty profile is also mentioned as vulnerable.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate risk. An EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the issue is not listed in CISA KEV. The likely attack vector is network‑based request smuggling. Based on the description, an attacker sending a specially crafted HTTP transfer‑encoding header could cause WebSphere to treat multiple requests as one, leading to cache poisoning, WAF bypass, and XSS. Successful exploitation can result in compromise of user sessions or sensitive data.

Generated by OpenCVE AI on September 20, 2026 at 22:07 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM WebSphere Application Server 9.0 fix pack 9.0.5.29 or later to all v9.0.x servers.
  • Apply IBM WebSphere Application Server 8.5 fix pack 8.5.5.31 or later to all v8.5.x servers.
  • If patching cannot be performed immediately, configure the server or any upstream proxy to strictly validate or reject malformed Transfer‑Encoding headers.
  • Monitor network traffic for patterns indicative of request smuggling and review application logs for cache‑poisoning or unexpected responses.

Generated by OpenCVE AI on September 20, 2026 at 22:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-444
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:48.776Z

Reserved: 2026-07-13T18:05:13.164Z

Link: CVE-2026-15634

cve-icon Vulnrichment

Updated: 2026-09-15T17:27:12.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:38.540

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-15634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')