CVE-2026-15064: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
Other sources
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 17.0.0.3 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.7Patch PH72191 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.0.0Patch PH72192 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.28Patch PH72192 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.0.0Patch PH72192 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.30Patch PH72192
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15064?
CVE-2026-15064 has a severity score of 8.7, classified as high risk.
How do I fix CVE-2026-15064?
To fix CVE-2026-15064, apply the latest patches and updates provided by IBM for WebSphere Application Server and Liberty.
What are the affected versions of CVE-2026-15064?
CVE-2026-15064 affects IBM WebSphere Application Server versions 9.0 and 8.5, as well as WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7.
What type of vulnerability is CVE-2026-15064?
CVE-2026-15064 is classified as an HTTP Response Smuggling vulnerability due to improper handling of non-standard HTTP version tokens.
What components are impacted by CVE-2026-15064?
CVE-2026-15064 impacts multiple components of IBM WebSphere Application Server and WebSphere Application Server Liberty.