Junglewise Threat Intelligence

CVE-2026-4410: IBM WebSphere Application Server denial of service in sipServlet-1.1

CVE-2026-4410 · Severity: medium · CVSS 4.8 · Published 2026-05-27

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a platform used to build and run enterprise web applications. A vulnerability in how the server handles specific network requests could allow an attacker to exhaust the server's memory. This would result in a denial of service, making hosted applications unavailable to legitimate users.

Technical details

A denial of service vulnerability exists in IBM WebSphere Application Server and Liberty due to improper resource management when processing specially crafted requests. In Liberty environments, this specifically affects instances with the sipServlet-1.1 feature enabled. An attacker with adjacent network access and low privileges can exploit this by sending malicious requests that trigger excessive memory consumption. This leads to resource exhaustion and eventual service unavailability. IBM has released interim fixes (APAR PH70807 and PH70616) and plans to include permanent fixes in upcoming fix packs (26.0.0.6, 9.0.5.28, and 8.5.5.30).

Affected products

  • IBM WebSphere Application Server - Liberty 19.0.0.7-26.0.0.5
  • IBM WebSphere Application Server 9.0.0.0-9.0.5.27, 8.5.0.0-8.5.5.29

Timeline

  • 2026-05-19: disclosed: Initial publication by IBM
  • 2026-05-27: advisory: NVD publication date

References

Related threats