Executive brief
IBM WebSphere Application Server is a platform used to host and run enterprise Java applications. A security flaw in how the server handles web traffic could allow an attacker to interfere with user sessions or bypass security controls by 'smuggling' malicious requests past front-end security filters. This could lead to unauthorized access to sensitive data or the modification of application behavior.
Technical details
IBM WebSphere Application Server (8.5, 9.0) and Liberty (17.0.0.3 through 26.0.0.6) are vulnerable to HTTP Request Smuggling (CWE-444). The vulnerability arises from inconsistent interpretation of HTTP requests between the application server and front-end proxies or load balancers. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests to the server. Successful exploitation could allow the attacker to poison web caches, bypass security constraints, or hijack user sessions. IBM has released interim fixes (APAR PH71808 and PH71706) and plans to include permanent fixes in upcoming Fix Packs (9.0.5.29, 8.5.5.31, and 26.0.0.7).
Affected products
- IBM WebSphere Application Server 8.5, 9.0
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.6
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-30: advisory: NVD publication date