CVE-2026-15057: IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
Other sources
IBM WebSphere Application Server Liberty is vulnerable to a denial of service due to uncontrolled heap allocation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Liberty (servlet-3.1, servlet-4.0, servlet-5.0, servlet-6.0, servlet-6.1)to a version that resolves this vulnerability.Fixed in 26.0.0.8Patch PH72167
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15057?
CVE-2026-15057 has a severity rating of 7.5, indicating a high risk of exploitation.
What types of attacks can exploit CVE-2026-15057?
CVE-2026-15057 can be exploited to perform a denial of service attack due to uncontrolled heap allocation.
Which versions of IBM WebSphere Application Server Liberty are affected by CVE-2026-15057?
CVE-2026-15057 affects IBM WebSphere Application Server Liberty versions from 17.0.0.3 through 26.0.0.7.
How do I fix CVE-2026-15057?
To mitigate CVE-2026-15057, upgrade your IBM WebSphere Application Server Liberty to a patched version that addresses this vulnerability.
What is the impact of CVE-2026-15057 on IBM WebSphere Application Server Liberty?
The impact of CVE-2026-15057 is a denial of service, potentially causing a service outage for applications running on affected versions.