Executive brief
IBM WebSphere Application Server (versions 8.5, 9.0, and Liberty) is vulnerable to HTTP request smuggling, a web protocol flaw that allows attackers to inject malicious requests into HTTP traffic. Exploiting this vulnerability could enable cache poisoning, session hijacking, or bypassing security controls on corporate application servers.
Technical details
HTTP request smuggling (CWE-444) occurs when inconsistent parsing of HTTP request boundaries between a reverse proxy and backend server allows an attacker to inject additional HTTP requests through a single connection. The vulnerability affects WebSphere 8.5, 9.0, and Liberty variants, exploitable over the network without authentication. An attacker can craft malicious HTTP requests to desynchronize the request stream, potentially leading to unauthorized access, cache poisoning, or credential theft. IBM has published security updates for affected versions.
Affected products
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server Liberty affected versions
Timeline
- 2026-09-18: disclosed: CVE-2026-10841 published