Executive brief
IBM WebSphere Extreme Scale, a high-performance data caching solution, is vulnerable to a denial-of-service attack. An attacker on the same local network can send specially crafted data that causes the application to crash by exhausting its memory or processing capacity. This results in a service outage, preventing legitimate users and applications from accessing cached data.
Technical details
IBM WebSphere Extreme Scale (versions 8.6.1.0 through 8.6.1.6) contains an uncontrolled resource consumption vulnerability (CWE-400) within its XDF decoder. The component fails to perform sufficient bounds checking on attacker-controlled length prefixes and deeply nested Protocol Buffers messages. An adjacent attacker can exploit this by sending malicious messages that trigger a StackOverflowError or OutOfMemoryError, leading to a crash of the WebSphere Application Server JVM. IBM has released APAR PH71946 to address this issue; users on 8.6.1.6 should apply the iFix, while those on older versions must first upgrade to 8.6.1.6.
Affected products
- IBM WebSphere Extreme Scale 8.6.1.0 - 8.6.1.6
Timeline
- 2026-06-29: advisory: Initial publication by IBM
- 2026-06-30: disclosed: NVD publication date