Executive brief
IBM HTTP Server, a web server component used by WebSphere Application Server, is vulnerable to a flaw that can cause the service to crash. By sending a specific request to the server, an attacker can trigger a system failure, making websites or applications hosted on the server unavailable to legitimate users. This impact is limited to service availability and does not involve the theft of customer data.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in the optional 'mod_ibm_upload' module of IBM HTTP Server versions 8.5 and 9.0. A remote, unauthenticated attacker can exploit this flaw by sending a specially crafted network request to the server. Successful exploitation results in a crash of the HTTP server process, leading to a denial of service condition. The vulnerability is addressed in APAR PH71265, and users are advised to apply the relevant interim fixes or upgrade to fix packs 8.5.5.30 or 9.0.5.29.
Affected products
- IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory