Junglewise Threat Intelligence

CVE-2026-9338: IBM WebSphere Application Server denial of service via crafted request

CVE-2026-9338 · Severity: medium · CVSS 5.3 · Published 2026-09-10

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a Java-based enterprise application platform used to host mission-critical business applications. A remote attacker can send a specially-crafted network request to trigger excessive resource consumption, causing the service to become unavailable or significantly degrade performance, impacting business operations and customer access.

Technical details

This vulnerability is a denial of service (DoS) flaw in IBM WebSphere Application Server versions 8.5 and 9.0, exploitable by sending a specially-crafted HTTP request to a network-accessible server. The root cause involves improper request handling that leads to excessive resource consumption, causing the application server process to become unresponsive or crash. The vulnerability requires no authentication and can be triggered from the network without user interaction. An attacker can leverage this to exhaust server resources (CPU, memory, or connections), rendering the application unavailable. Patches are available in versions 8.5.5.31 and 9.0.5.29 or later.

Affected products

  • IBM WebSphere Application Server 8.5, 9.0

Timeline

  • 2026-09-10: disclosed

References

Related threats