Executive brief
IBM WebSphere Application Server is a platform used to host and run enterprise Java applications. A vulnerability has been identified where a remote attacker can send a specially crafted request to the server, causing it to consume excessive memory. This can lead to a denial-of-service condition, making the hosted applications and services unavailable to legitimate users.
Technical details
IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to uncontrolled resource consumption (CWE-400). The flaw is triggered when the server processes a specially crafted network request, leading to excessive memory exhaustion. This is a remote, unauthenticated attack vector with low complexity. On Liberty, the vulnerability specifically affects environments with certain features enabled, such as servlet or websocket features. IBM has released interim fixes (PH71631 and PH71370) and plans to include permanent fixes in upcoming fix packs (26.0.0.7, 9.0.5.29, and 8.5.5.30).
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.6
Timeline
- 2026-06-16: advisory: Initial publication by IBM
- 2026-06-22: disclosed: NVD publication date