Executive brief
IBM DataPower Gateway, a security and integration platform for mobile, web, and API workloads, is vulnerable to a denial of service attack. A remote attacker can exploit improper resource management to overwhelm the system, potentially causing it to crash or become unresponsive. This could disrupt business operations by preventing legitimate traffic and applications from passing through the gateway.
Technical details
IBM DataPower Gateway is vulnerable to a denial of service (DoS) attack due to improper resource limitations (CWE-770). The vulnerability is specifically related to the handling of HTTP/2 traffic, where the system fails to properly throttle or limit resource allocation. A remote, unauthenticated attacker can exploit this by sending specially crafted requests over the network, leading to resource exhaustion and a complete loss of availability. IBM has released firmware updates to address this issue. As a temporary mitigation, administrators can disable HTTP/2 support if immediate patching is not possible.
Affected products
- IBM DataPower Gateway 10.5.0 10.5.0.0 - 10.5.0.21
- IBM DataPower Gateway 10.6.0 10.6.0.0 - 10.6.0.9
- IBM DataPower Gateway 10.6CD 10.6.1 - 10.6.6
- IBM DataPower Gateway 11.0.0 11.0.0.0 - 11.0.0.1
Timeline
- 2026-07-01: disclosed: Initial publication by IBM
- 2026-07-01: patched: Fixes released in versions 10.5.0.22, 10.6.0.10, and 11.0.0.2
- 2026-07-30: advisory: NVD publication date