Junglewise Threat Intelligence

CVE-2026-10841: IBM WebSphere Application Server HTTP request smuggling

CVE-2026-10841 · Severity: medium · CVSS 4.2 · Published 2026-09-18

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server (versions 8.5, 9.0, and Liberty) is vulnerable to HTTP request smuggling, a web protocol flaw that allows attackers to inject malicious requests into HTTP traffic. Exploiting this vulnerability could enable cache poisoning, session hijacking, or bypassing security controls on corporate application servers.

Technical details

HTTP request smuggling (CWE-444) occurs when inconsistent parsing of HTTP request boundaries between a reverse proxy and backend server allows an attacker to inject additional HTTP requests through a single connection. The vulnerability affects WebSphere 8.5, 9.0, and Liberty variants, exploitable over the network without authentication. An attacker can craft malicious HTTP requests to desynchronize the request stream, potentially leading to unauthorized access, cache poisoning, or credential theft. IBM has published security updates for affected versions.

Affected products

  • IBM WebSphere Application Server 8.5, 9.0
  • IBM WebSphere Application Server Liberty affected versions

Timeline

  • 2026-09-18: disclosed: CVE-2026-10841 published

References

Related threats