CVE-2026-10571: IBM WebSphere Application Server Liberty is affected by a denial of service
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
Other sources
IBM WebSphere Application Server Liberty is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.9Patch DT497316 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Patch DT497316
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10571?
The severity of CVE-2026-10571 is classified as medium with a CVSS score of 5.7.
How do I fix CVE-2026-10571?
To fix CVE-2026-10571, upgrade IBM WebSphere Application Server Liberty to version 26.0.0.9 or later.
What types of attacks can occur due to CVE-2026-10571?
CVE-2026-10571 can lead to denial of service attacks that consume system resources.
Who can exploit CVE-2026-10571?
A low-privileged administrative user can exploit CVE-2026-10571 if the restConnector-2.0 feature is enabled.
What versions of IBM WebSphere Application Server Liberty are affected by CVE-2026-10571?
CVE-2026-10571 affects IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.8.