Junglewise Threat Intelligence

CVE-2026-8850: IBM HTTP Server denial of service in mod_ibm_upload

CVE-2026-8850 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a flaw that can cause the service to crash. By sending a specific request to the server, an attacker can trigger a system failure, making websites or applications hosted on the server unavailable to legitimate users. This impact is limited to service availability and does not involve the theft of customer data.

Technical details

A NULL pointer dereference vulnerability (CWE-476) exists in the optional 'mod_ibm_upload' module of IBM HTTP Server versions 8.5 and 9.0. A remote, unauthenticated attacker can exploit this flaw by sending a specially crafted network request to the server. Successful exploitation results in a crash of the HTTP server process, leading to a denial of service condition. The vulnerability is addressed in APAR PH71265, and users are advised to apply the relevant interim fixes or upgrade to fix packs 8.5.5.30 or 9.0.5.29.

Affected products

  • IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory

References