Junglewise Threat Intelligence

CVE-2026-11897: IBM WebSphere Application Server Liberty denial of service in HTTP/2

CVE-2026-11897 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

IBM WebSphere Application Server Liberty, a popular platform for building and running Java applications, is vulnerable to a denial-of-service attack. By sending a specifically crafted request, a remote attacker can force the server to consume excessive memory resources. This can lead to application crashes or significant performance degradation, preventing legitimate users from accessing the service.

Technical details

IBM WebSphere Application Server Liberty is vulnerable to a Denial of Service (DoS) attack due to improper resource management (CWE-770) when handling HTTP/2 requests. The vulnerability is present when specific servlet features (servlet-3.1 through servlet-6.1) are enabled. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP/2 requests that trigger excessive memory allocation. This can lead to resource exhaustion and server instability. The issue is addressed in Liberty Fix Pack 26.0.0.8 or via interim fix PH71839.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7

Timeline

  • 2026-07-21: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats