HTTP Request Smuggling Vulnerability in IBM WebSphere Application Server
CVE-2026-11541

7.4HIGH

What is CVE-2026-11541?

An HTTP request smuggling vulnerability has been identified in IBM WebSphere Application Server versions 9.0 and 8.5, along with Liberty versions 17.0.0.3 through 26.0.0.6. This vulnerability potentially allows an attacker to manipulate the way requests are processed, leading to unauthorized access or exposure of sensitive information. It is crucial for users of the affected versions to apply patches and follow mitigation strategies provided by IBM to safeguard their applications.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.6

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.