Denial of Service Vulnerability in IBM DataPower Gateway
CVE-2026-16182

5.9MEDIUM

What is CVE-2026-16182?

A vulnerability in IBM DataPower Gateway could be exploited to trigger a denial of service condition. This occurs due to a NULL pointer dereference during the processing of GraphQL variables, potentially allowing an attacker to disrupt service operations. Users are advised to review the advisory and apply relevant patches to safeguard against this vulnerability.

Affected Version(s)

DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22

DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10

DataPower Gateway 10.6CD 10.6.1 <= 10.6.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.