Executive brief
IBM WebSphere Application Server and WebSphere Application Server Liberty, which run enterprise Java applications, are vulnerable to HTTP request smuggling. This vulnerability allows attackers to bypass security controls, gain unauthorized access to sensitive data, or perform actions they should not be permitted to execute.
Technical details
HTTP request smuggling occurs when the application server inconsistently parses malformed or ambiguous HTTP requests, allowing attackers to inject hidden requests that the server processes differently than intended. This can lead to request processing confusion, cache poisoning, or authentication bypass. The vulnerability affects both the full WebSphere Application Server product and the lightweight Liberty variant.
Affected products
- IBM WebSphere Application Server <UNKNOWN>
- IBM WebSphere Application Server Liberty <UNKNOWN>
Timeline
- 2026-09-18: disclosed