HTTP Response Smuggling Vulnerability in IBM WebSphere Application Server
CVE-2026-15064
8.7HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15064?
IBM WebSphere Application Server versions 8.5, 9.0, and the Liberty edition from 17.0.0.3 to 26.0.0.7 are susceptible to a vulnerability that allows attackers to conduct HTTP Response Smuggling. This flaw arises from the improper handling of non-standard HTTP version tokens, potentially enabling malicious actors to exploit the server's HTTP requests and responses. This could lead to various types of attacks, such as cache poisoning, session hijacking, and bypassing security controls. Organizations using affected versions should verify their systems and apply necessary patches to mitigate the risk.
Affected Version(s)
WebSphere Application Server 9.0
WebSphere Application Server 8.5
WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.7