Executive brief
IBM WebSphere Application Server and Liberty are widely used platforms for hosting enterprise Java applications. A vulnerability in the way these servers handle web traffic could allow an attacker to crash the service or make it unresponsive by exhausting its available resources. This could lead to a total outage of hosted business applications, impacting customer access and internal operations.
Technical details
IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to a Denial of Service (DoS) attack due to uncontrolled resource consumption (CWE-400) within the HTTP channel. The flaw stems from unbounded allocation of resources when processing requests, which can be triggered by a remote, unauthenticated attacker. For Liberty environments, the vulnerability is specifically present when servlet features (3.0 through 6.1) are enabled. Exploitation allows an attacker to exhaust system resources, leading to service instability or a complete crash. IBM has released interim fixes (PH72191 and PH72192) and plans to include permanent fixes in upcoming Fix Packs (9.0.5.29, 8.5.5.31, and 26.0.0.8).
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7
Timeline
- 2026-07-28: disclosed: Initial publication by IBM
- 2026-07-28: patched: Interim fixes PH72191 and PH72192 released