Junglewise Threat Intelligence

CVE-2026-9336: IBM WebSphere Application Server denial of service via HTTP request

CVE-2026-9336 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is an application server that runs business-critical enterprise applications. A remote attacker can send a specially crafted HTTP request to an administrative endpoint to cause the server to exhaust filesystem space, leading to service degradation or outage. No authentication is required to exploit this vulnerability.

Technical details

This is a denial of service vulnerability in IBM WebSphere Application Server 8.5 and 9.0 caused by improper handling of a specially crafted HTTP request sent to an administrative endpoint. The vulnerability allows a remote attacker to exhaust filesystem space on the affected server, triggering a denial of service condition. The attack requires only network access to the administrative endpoint and no authentication. Fixes are available in WebSphere Application Server 9.0.5.29 and 8.5.5.31 or later.

Affected products

  • IBM WebSphere Application Server 8.5 through 8.5.5.30, 9.0 through 9.0.5.28

Timeline

  • 2026-09-10: disclosed

References

Related threats