Executive brief
IBM WebSphere Application Server Liberty, a platform for developing and running Java applications, is vulnerable to a denial of service attack. If the restConnector feature is enabled, an attacker can cause the server to crash or become unresponsive, disrupting business operations and application availability. This issue affects versions 17.0.0.3 through 26.0.0.8 and requires a software update to resolve.
Technical details
IBM WebSphere Application Server Liberty is vulnerable to a denial of service (DoS) caused by uncontrolled recursion (CWE-674). The vulnerability exists within the restConnector-1.0 and restConnector-2.0 features. A remote authenticated attacker can exploit this flaw to trigger excessive resource consumption or a stack overflow, leading to a crash of the application server. The attack vector is network-based with low complexity, though it requires basic user privileges. IBM has released interim fix DT496294 and recommends upgrading to Liberty Fix Pack 26.0.0.9 or later to mitigate the risk.
Affected products
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory