Junglewise Threat Intelligence

CVE-2026-9322: IBM WebSphere Application Server denial of service via crafted HTTP request

CVE-2026-9322 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

IBM WebSphere Application Server, a platform used to build and run enterprise applications, is vulnerable to a denial-of-service attack. An attacker can send a specially crafted web request that causes the server to become unresponsive or crash by exhausting its resources. This could lead to an outage of business-critical applications hosted on the server, impacting availability for customers and employees.

Technical details

IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to a denial of service (DoS) classified as uncontrolled resource consumption (CWE-400). The vulnerability is triggered when the server processes a specially crafted HTTP request, which can lead to memory exhaustion or other resource depletion. The attack is network-reachable, requires no authentication, and involves no user interaction. Affected Liberty environments are specifically those utilizing features such as JAX-RS, JSON, and JAX-WS. IBM has released interim fixes (PH71585 and PH71670) and plans to include permanent fixes in Fix Packs 26.0.0.8, 9.0.5.29, and 8.5.5.31.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.30
  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7

Timeline

  • 2026-06-30: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats