Junglewise Threat Intelligence

CVE-2026-15396: IBM WebSphere Application Server HTTP request smuggling via transfer-encoding

CVE-2026-15396 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a Java-based middleware platform used to host enterprise web applications. This vulnerability allows an attacker to manipulate how HTTP requests are interpreted by sending specially crafted transfer-encoding headers, enabling cache poisoning, firewall bypass, and cross-site scripting attacks without requiring authentication.

Technical details

This is an HTTP request smuggling vulnerability (CWE-444) caused by improper parsing of the HTTP transfer-encoding request header in the request processing logic. The vulnerability affects WebSphere Application Server 9.0 prior to 9.0.5.29 and 8.5 prior to 8.5.5.31, as well as WebSphere Application Server Liberty. An unauthenticated attacker on the network can send a specially crafted transfer-encoding header to create a discrepancy between how the application server and upstream proxies/caches interpret the request boundary, allowing request smuggling attacks. Successful exploitation enables cache poisoning, web application firewall bypass, and XSS injection. IBM has issued patches in versions 9.0.5.29 and 8.5.5.31.

Affected products

  • IBM WebSphere Application Server 9.0 prior to 9.0.5.29, 8.5 prior to 8.5.5.31
  • IBM WebSphere Application Server Liberty affected versions not explicitly stated

Timeline

  • 2026-09-14: disclosed

References

Related threats