HTTP Response Smuggling Vulnerability in IBM WebSphere Application Server
CVE-2026-15064

8.7HIGH

What is CVE-2026-15064?

IBM WebSphere Application Server versions 8.5, 9.0, and the Liberty edition from 17.0.0.3 to 26.0.0.7 are susceptible to a vulnerability that allows attackers to conduct HTTP Response Smuggling. This flaw arises from the improper handling of non-standard HTTP version tokens, potentially enabling malicious actors to exploit the server's HTTP requests and responses. This could lead to various types of attacks, such as cache poisoning, session hijacking, and bypassing security controls. Organizations using affected versions should verify their systems and apply necessary patches to mitigate the risk.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.7

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.