Executive brief
IBM HTTP Server is a web server component used within the WebSphere Application Server environment. A vulnerability in an optional module could allow a local attacker to cause a denial of service, effectively crashing the web server and disrupting hosted applications. This impact is limited to service availability and does not involve the theft of customer data.
Technical details
IBM HTTP Server is vulnerable to a denial of service caused by a reachable assertion (CWE-617) within the optional mod_fastcgi module. A local attacker can exploit this flaw to trigger an assertion failure, leading to a process crash and service interruption. The vulnerability is tracked under APAR PH71265. While the attack vector is classified as local, it requires no specific privileges or user interaction to execute. IBM has released interim fixes and recommends upgrading to fix packs 8.5.5.30 or 9.0.5.29 to resolve the issue.
Affected products
- IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory
- 2026-05-26: patched: Interim fixes released; Fix Packs scheduled for 3Q2026