CVE-2026-15328: IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
Other sources
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72192 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH72191
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15328?
CVE-2026-15328 has a high severity rating of 7.4.
What systems are affected by CVE-2026-15328?
CVE-2026-15328 affects IBM WebSphere Application Server versions 9.0, 8.5, and IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7.
How do I fix CVE-2026-15328?
To remediate CVE-2026-15328, upgrade to the latest version of IBM WebSphere Application Server or WebSphere Application Server - Liberty that addresses this vulnerability.
What is HTTP request smuggling in the context of CVE-2026-15328?
HTTP request smuggling in CVE-2026-15328 refers to the inconsistent interpretation of HTTP requests by the affected WebSphere Application Servers, which can lead to various security issues.
What potential impact does CVE-2026-15328 have on my applications?
CVE-2026-15328 can lead to unauthorized data exposure and manipulation, potentially compromising the security and integrity of applications deployed on the affected servers.