Junglewise Threat Intelligence

CVE-2026-15064: IBM WebSphere Application Server HTTP response smuggling

CVE-2026-15064 · Severity: high · CVSS 8.7 · Published 2026-07-28

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to build and run enterprise applications, is vulnerable to a security flaw that could allow attackers to interfere with web traffic. By sending specially crafted web requests, an attacker could potentially bypass security controls, hijack user sessions, or gain unauthorized access to sensitive data. This issue affects both the traditional version of the server and the lightweight Liberty edition when specific web features are enabled.

Technical details

IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to HTTP Response Smuggling (CWE-444). The vulnerability stems from the improper handling of non-standard HTTP version tokens within the HTTP channel. An attacker can exploit this by sending specially crafted HTTP requests to the server, potentially leading to the poisoning of web caches or the bypassing of security constraints. This vulnerability is present when servlet features (3.0 through 6.1) are enabled. IBM has released interim fixes (PH72191 and PH72192) and plans to include permanent fixes in upcoming Fix Packs (26.0.0.8, 9.0.5.29, and 8.5.5.31).

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched: Interim fixes released; Fix Packs scheduled for 3Q2026

References

Related threats