Junglewise Threat Intelligence

CVE-2026-11548: IBM WebSphere Application Server HTTP request smuggling

CVE-2026-11548 · Severity: medium · CVSS 4.8 · Published 2026-09-18

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server and WebSphere Application Server Liberty, which run enterprise Java applications, are vulnerable to HTTP request smuggling. This vulnerability allows attackers to bypass security controls, gain unauthorized access to sensitive data, or perform actions they should not be permitted to execute.

Technical details

HTTP request smuggling occurs when the application server inconsistently parses malformed or ambiguous HTTP requests, allowing attackers to inject hidden requests that the server processes differently than intended. This can lead to request processing confusion, cache poisoning, or authentication bypass. The vulnerability affects both the full WebSphere Application Server product and the lightweight Liberty variant.

Affected products

  • IBM WebSphere Application Server <UNKNOWN>
  • IBM WebSphere Application Server Liberty <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References

Related threats