Executive brief
IBM Aspera High-Speed Transfer Server and Endpoint are enterprise solutions used for moving large files and data sets at high speeds across global networks. A vulnerability in the 'asperahttpd' component allows an unauthenticated remote attacker to crash the service, leading to a denial of service. This could disrupt critical data transfer operations and business workflows that rely on automated or manual high-speed file delivery.
Technical details
The vulnerability is classified as a NULL pointer dereference (CWE-476) within the 'asperahttpd' component of IBM Aspera High-Speed Transfer Server and Endpoint. It can be triggered by an unauthenticated attacker over the network with low complexity and no user interaction required. Successful exploitation results in the 'asperahttpd' service crashing, leading to a complete loss of availability for the affected component. The issue is addressed in IBM Aspera High-Speed Transfer Server and Endpoint version 4.4.7 Fix Pack 2.
Affected products
- IBM Aspera High-Speed Transfer Endpoint 3.7.4 - 4.4.7 Fix Pack 1
- IBM Aspera High-Speed Transfer Server 3.7.4 - 4.4.7 Fix Pack 1
Timeline
- 2026-05-21: advisory: Initial publication by IBM
- 2026-05-22: other: Updated product versions in document information
- 2026-05-27: disclosed: NVD publication date