Executive brief
IBM WebSphere Application Server is a Java-based middleware platform used to host enterprise web applications. This vulnerability allows an attacker to manipulate how HTTP requests are interpreted by sending specially crafted transfer-encoding headers, enabling cache poisoning, firewall bypass, and cross-site scripting attacks without requiring authentication.
Technical details
This is an HTTP request smuggling vulnerability (CWE-444) caused by improper parsing of the HTTP transfer-encoding request header in the request processing logic. The vulnerability affects WebSphere Application Server 9.0 prior to 9.0.5.29 and 8.5 prior to 8.5.5.31, as well as WebSphere Application Server Liberty. An unauthenticated attacker on the network can send a specially crafted transfer-encoding header to create a discrepancy between how the application server and upstream proxies/caches interpret the request boundary, allowing request smuggling attacks. Successful exploitation enables cache poisoning, web application firewall bypass, and XSS injection. IBM has issued patches in versions 9.0.5.29 and 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0 prior to 9.0.5.29, 8.5 prior to 8.5.5.31
- IBM WebSphere Application Server Liberty affected versions not explicitly stated
Timeline
- 2026-09-14: disclosed