Executive brief
IBM WebSphere Application Server, a Java-based platform for running enterprise web applications, is vulnerable to HTTP request smuggling through improper handling of Content-Length headers. An attacker could exploit this flaw over the network to smuggle malicious requests past security controls, potentially bypassing authentication, poisoning caches, or gaining unauthorized access to sensitive data.
Technical details
The vulnerability stems from inconsistent interpretation of HTTP requests (CWE-444) caused by improper Content-Length header handling in the HTTP request parsing logic. An unauthenticated network attacker with no user interaction required can craft malformed requests to desynchronize the HTTP layer, allowing request smuggling attacks. A fix is available in Fix Pack 8.5.5.31 or later.
Affected products
- IBM WebSphere Application Server 8.5.0.0 through 8.5.5.30
Timeline
- 2026-09-08: disclosed
- 2026-09: patched: Fix Pack 8.5.5.31 availability expected September 2026