Junglewise Threat Intelligence

CVE-2026-9320: IBM WebSphere Application Server denial of service via memory exhaustion

CVE-2026-9320 · Severity: medium · CVSS 5.9 · Published 2026-06-22

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server and WebSphere Liberty are vulnerable to a denial of service attack. By sending a specifically crafted network request, a remote attacker can force the server to consume excessive memory resources. This can lead to significant performance degradation or a complete service outage, preventing legitimate users from accessing hosted applications.

Technical details

IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to uncontrolled resource consumption (CWE-400). The vulnerability is triggered when the server processes a specially-crafted HTTP request, leading to excessive memory consumption. On WebSphere Liberty, this specifically affects environments with certain features enabled, such as servlet or websocket features. A remote, unauthenticated attacker can exploit this over the network to cause a denial of service (DoS) condition. While the attack vector is network-based, the complexity is rated as high. IBM has released interim fixes (PH71631 and PH71370) and plans to include permanent fixes in upcoming Fix Packs (9.0.5.29, 8.5.5.30, and 26.0.0.7).

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29
  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.6

Timeline

  • 2026-06-16: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats