CVE-2026-14981: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Other sources
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server - Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server - traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server - traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72191
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14981?
CVE-2026-14981 has a severity rating of 7.5, classified as high.
How do I fix CVE-2026-14981?
To fix CVE-2026-14981, apply the latest patches provided by IBM for the affected versions of WebSphere Application Server and Liberty.
What types of systems are affected by CVE-2026-14981?
CVE-2026-14981 affects IBM WebSphere Application Server 9.0, 8.5, and IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7.
What is the risk associated with CVE-2026-14981?
CVE-2026-14981 presents a risk of denial of service due to unbounded resource allocation in the HTTP channel.
When was CVE-2026-14981 published?
CVE-2026-14981 was published on July 28, 2026.