Junglewise Threat Intelligence

CVE-2026-11710: IBM WebSphere Application Server HTTP request smuggling

CVE-2026-11710 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a Java-based platform for running enterprise web applications, is vulnerable to HTTP request smuggling through improper handling of Content-Length headers. An attacker could exploit this flaw over the network to smuggle malicious requests past security controls, potentially bypassing authentication, poisoning caches, or gaining unauthorized access to sensitive data.

Technical details

The vulnerability stems from inconsistent interpretation of HTTP requests (CWE-444) caused by improper Content-Length header handling in the HTTP request parsing logic. An unauthenticated network attacker with no user interaction required can craft malformed requests to desynchronize the HTTP layer, allowing request smuggling attacks. A fix is available in Fix Pack 8.5.5.31 or later.

Affected products

  • IBM WebSphere Application Server 8.5.0.0 through 8.5.5.30

Timeline

  • 2026-09-08: disclosed
  • 2026-09: patched: Fix Pack 8.5.5.31 availability expected September 2026

References

Related threats