Junglewise Threat Intelligence

CVE-2026-11722: IBM WebSphere Application Server HTTP request smuggling

CVE-2026-11722 · Severity: medium · CVSS 4.8 · Published 2026-09-18

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server (both traditional and Liberty editions) contains an HTTP request smuggling vulnerability that could allow attackers to bypass security controls or manipulate requests. The vulnerability affects web application servers that process HTTP traffic, and successful exploitation could lead to request interception, cache poisoning, or unauthorized access to backend systems.

Technical details

HTTP request smuggling arises from inconsistent interpretation of HTTP request boundaries between the front-end proxy and backend server. An attacker can craft malformed requests to trick the server into processing unintended commands, typically requiring network access but no authentication. Exploitation may expose backend functionality or enable session hijacking.

Affected products

  • IBM WebSphere Application Server multiple versions
  • IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.8

Timeline

  • 2026-09-18: disclosed

References

Related threats