Junglewise Threat Intelligence

CVE-2026-8175: IBM Aspera High-Speed Transfer heap overflow in asperahttpd

CVE-2026-8175 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Technologies: IBM Aspera High-Speed Transfer Server, IBM Aspera High-Speed Transfer Endpoint. Vendors: IBM.

Executive brief

IBM Aspera High-Speed Transfer products, which are used for rapid large-scale data transfers, contain a critical security flaw in their web handling component. An attacker could exploit this to crash the service, bypass security controls, or take full control of the server. This could lead to unauthorized access to sensitive files, data theft, or a complete disruption of file transfer operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in the asperahttpd component of IBM Aspera High-Speed Transfer Server and Endpoint. The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). By sending specially crafted requests to the affected component, a remote attacker can trigger the overflow to cause a denial of service (service crash), bypass authentication mechanisms, or achieve arbitrary remote code execution (RCE) with the privileges of the asperahttpd process. IBM has released 4.4.7 Fix Pack 2 to address this issue.

Affected products

  • IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1
  • IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1

Timeline

  • 2026-05-21: advisory: Initial publication by IBM
  • 2026-05-22: other: Updated product versions in advisory
  • 2026-05-27: disclosed: NVD publication date

References

Related threats