Denial of Service Vulnerability in IBM WebSphere Extreme Scale
CVE-2026-9002

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-9002?

IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a vulnerability in the XDF decoder that may allow an adjacent attacker to manipulate deeply nested Protocol Buffers messages. Due to improper validation of attacker-controlled length prefixes, an attacker on the same network could exploit this flaw to trigger a StackOverflowError or OutOfMemoryError, leading to a crash of the WebSphere Application Server's JVM. This vulnerability underscores the importance of implementing robust input validation and bounds checking in application protocols.

Affected Version(s)

WebSphere Extreme Scale 8.6.1.0 <= 8.6.1.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.