Executive brief
IBM WebSphere Application Server, a platform used to build and run enterprise applications, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted web request that causes the server to become unresponsive or crash by exhausting its resources. This could lead to an outage of business-critical applications hosted on the server, impacting availability for customers and employees.
Technical details
IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to a denial of service (DoS) classified as uncontrolled resource consumption (CWE-400). The vulnerability is triggered when the server processes a specially crafted HTTP request, which can lead to memory exhaustion or other resource depletion. The attack is network-reachable, requires no authentication, and involves no user interaction. Affected Liberty environments are specifically those utilizing features such as JAX-RS, JSON, and JAX-WS. IBM has released interim fixes (PH71585 and PH71670) and plans to include permanent fixes in Fix Packs 26.0.0.8, 9.0.5.29, and 8.5.5.31.
Affected products
- IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
- IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7
Timeline
- 2026-06-30: disclosed: Initial publication by IBM
- 2026-07-30: advisory: NVD publication date