Junglewise Threat Intelligence

CVE-2026-8620: IBM WebSphere Application Server HTTP request smuggling in Web Server Plug-ins

CVE-2026-8620 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM WebSphere Application Server and WebSphere Liberty are affected by a security flaw in their web server plug-ins. This vulnerability allows an attacker to manipulate how the server interprets web requests, potentially leading to unauthorized access to sensitive data or the ability to bypass security controls. Organizations using these plug-ins should apply the available security updates to prevent attackers from interfering with web traffic.

Technical details

IBM WebSphere Application Server and WebSphere Liberty are vulnerable to HTTP request smuggling (CWE-444) within the Web Server Plug-ins component. The vulnerability arises from inconsistent interpretation of HTTP requests between the plug-in and the backend server. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the server. Successful exploitation could allow an attacker to bypass security constraints, access sensitive information, or poison web caches. The vulnerability is addressed by applying interim fix PH71342 or upgrading to fix packs 9.0.5.28 and 8.5.5.30 or later.

Affected products

  • IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5.0.0 - 8.5.5.29, 9.0.0.0 - 9.0.5.27

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Interim fix PH71342 released

References