Heap Buffer Underwrite Vulnerability in IBM DataPower Gateway
CVE-2026-16179
7.5HIGH
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16179?
A vulnerability exists in IBM DataPower Gateway that could allow an attacker to trigger a heap buffer underwrite. This flaw may lead to a service crash, affecting the availability of the gateway. Users are advised to review the implementation versions and apply necessary patches to mitigate risks associated with this vulnerability.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6