Junglewise Threat Intelligence

CVE-2026-9002: IBM WebSphere Extreme Scale denial of service in XDF decoder

CVE-2026-9002 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Technologies: IBM Websphere Extreme Scale. Vendors: IBM.

Executive brief

IBM WebSphere Extreme Scale, a high-performance data caching solution, is vulnerable to a denial-of-service attack. An attacker on the same local network can send specially crafted data that causes the application to crash by exhausting its memory or processing capacity. This results in a service outage, preventing legitimate users and applications from accessing cached data.

Technical details

IBM WebSphere Extreme Scale (versions 8.6.1.0 through 8.6.1.6) contains an uncontrolled resource consumption vulnerability (CWE-400) within its XDF decoder. The component fails to perform sufficient bounds checking on attacker-controlled length prefixes and deeply nested Protocol Buffers messages. An adjacent attacker can exploit this by sending malicious messages that trigger a StackOverflowError or OutOfMemoryError, leading to a crash of the WebSphere Application Server JVM. IBM has released APAR PH71946 to address this issue; users on 8.6.1.6 should apply the iFix, while those on older versions must first upgrade to 8.6.1.6.

Affected products

  • IBM WebSphere Extreme Scale 8.6.1.0 - 8.6.1.6

Timeline

  • 2026-06-29: advisory: Initial publication by IBM
  • 2026-06-30: disclosed: NVD publication date

References

Related threats