Executive brief
IBM WebSphere Application Server (both traditional and Liberty editions) contains an HTTP request smuggling vulnerability that could allow attackers to bypass security controls or manipulate requests. The vulnerability affects web application servers that process HTTP traffic, and successful exploitation could lead to request interception, cache poisoning, or unauthorized access to backend systems.
Technical details
HTTP request smuggling arises from inconsistent interpretation of HTTP request boundaries between the front-end proxy and backend server. An attacker can craft malformed requests to trick the server into processing unintended commands, typically requiring network access but no authentication. Exploitation may expose backend functionality or enable session hijacking.
Affected products
- IBM WebSphere Application Server multiple versions
- IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.8
Timeline
- 2026-09-18: disclosed