CVE-2026-14269: IBM DataPower Gateway Buffer Overflow
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.
Other sources
IBM DataPower Gateway is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataPower Gateway 10.6CDto a version that resolves this vulnerability.Fixed in 11.0.0.3 - Upgrade
Upgrade
IBM DataPower Gateway 10.6.0to a version that resolves this vulnerability.Fixed in 10.6.0.11 - Upgrade
Upgrade
IBM DataPower Gateway 11.0.0to a version that resolves this vulnerability.Fixed in 11.0.0.3 - Upgrade
Upgrade
IBM DataPower Gateway 10.5.0to a version that resolves this vulnerability.Fixed in 10.5.0.23