Executive brief
IBM WebSphere Application Server Liberty, a popular platform for building and running Java applications, is vulnerable to a flaw that can crash the server. An attacker can exploit this by sending specific requests that cause the system to exhaust its memory. This results in a denial of service, making hosted applications and services unavailable to legitimate users.
Technical details
IBM WebSphere Application Server Liberty is vulnerable to a denial of service (DoS) caused by uncontrolled heap allocation and an out-of-bounds write (CWE-787). The vulnerability is present when the servlet-3.1, 4.0, 5.0, 6.0, or 6.1 features are enabled. A remote, unauthenticated attacker can exploit this flaw over the network by sending specially crafted requests that trigger excessive memory allocation, leading to a crash or system instability. The issue is tracked via APAR PH72167. Users are advised to upgrade to Liberty Fix Pack 26.0.0.8 or apply the provided interim fixes.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7
Timeline
- 2026-07-21: disclosed: Initial publication by IBM
- 2026-07-28: advisory: NVD publication date