Junglewise Threat Intelligence

CVE-2026-9170: IBM WebSphere Application Server HTTP request smuggling in Web Server Plug-ins

CVE-2026-9170 · Severity: high · CVSS 7.5 · Published 2026-05-26

Technologies: IBM WebSphere Application Server Liberty. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a platform used to host and manage enterprise Java applications. A vulnerability in its web server plug-in component could allow an attacker to interfere with how the server processes web requests. This can lead to unauthorized access to sensitive information or disruptions to the application's availability.

Technical details

IBM WebSphere Application Server and WebSphere Liberty are vulnerable to HTTP request smuggling (CWE-444) within the Web Server Plug-ins component. The vulnerability is caused by improper validation of input in specially crafted HTTP requests. A remote attacker can exploit this by sending a malicious request that the plug-in interprets differently than the backend server, potentially allowing the attacker to bypass security controls, access sensitive data, or cause a denial of service. The attack requires a high level of complexity to execute successfully. IBM has released interim fixes under APAR PH71342 and recommends upgrading to versions 8.5.5.30 or 9.0.5.28.

Affected products

  • IBM Web Server Plug-ins for WebSphere Application Server 8.5.0.0 - 8.5.5.29, 9.0.0.0 - 9.0.5.27
  • IBM WebSphere Application Server Liberty 8.5, 9.0

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched

References

Related threats