Junglewise Threat Intelligence

CVE-2026-15057: IBM WebSphere Application Server Liberty denial of service via uncontrolled heap allocation

CVE-2026-15057 · Severity: high · CVSS 7.5 · Published 2026-07-28

Technologies: IBM WebSphere Application Server Liberty. Vendors: IBM.

Executive brief

IBM WebSphere Application Server Liberty, a popular platform for building and running Java applications, is vulnerable to a flaw that can crash the server. An attacker can exploit this by sending specific requests that cause the system to exhaust its memory. This results in a denial of service, making hosted applications and services unavailable to legitimate users.

Technical details

IBM WebSphere Application Server Liberty is vulnerable to a denial of service (DoS) caused by uncontrolled heap allocation and an out-of-bounds write (CWE-787). The vulnerability is present when the servlet-3.1, 4.0, 5.0, 6.0, or 6.1 features are enabled. A remote, unauthenticated attacker can exploit this flaw over the network by sending specially crafted requests that trigger excessive memory allocation, leading to a crash or system instability. The issue is tracked via APAR PH72167. Users are advised to upgrade to Liberty Fix Pack 26.0.0.8 or apply the provided interim fixes.

Affected products

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7

Timeline

  • 2026-07-21: disclosed: Initial publication by IBM
  • 2026-07-28: advisory: NVD publication date

References

Related threats