IBM WebSphere Application Server 9.0 and 8.5 and IBM...
High severity
Unreviewed
Published
Jun 22, 2026
to the GitHub Advisory Database
•
Updated Jun 22, 2026
Description
Published by the National Vulnerability Database
Jun 22, 2026
Published to the GitHub Advisory Database
Jun 22, 2026
Last updated
Jun 22, 2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
References