Junglewise Threat Intelligence

CVE-2026-8852: IBM HTTP Server denial of service in mod_fastcgi

CVE-2026-8852 · Severity: medium · CVSS 6.2 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM HTTP Server is a web server component used within the WebSphere Application Server environment. A vulnerability in an optional module could allow a local attacker to cause a denial of service, effectively crashing the web server and disrupting hosted applications. This impact is limited to service availability and does not involve the theft of customer data.

Technical details

IBM HTTP Server is vulnerable to a denial of service caused by a reachable assertion (CWE-617) within the optional mod_fastcgi module. A local attacker can exploit this flaw to trigger an assertion failure, leading to a process crash and service interruption. The vulnerability is tracked under APAR PH71265. While the attack vector is classified as local, it requires no specific privileges or user interaction to execute. IBM has released interim fixes and recommends upgrading to fix packs 8.5.5.30 or 9.0.5.29 to resolve the issue.

Affected products

  • IBM HTTP Server 8.5.0.0 through 8.5.5.29, 9.0.0.0 through 9.0.5.28

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Interim fixes released; Fix Packs scheduled for 3Q2026

References