CVE-2026-15634: XSS
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafted HTTP transfer-encoding request header, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software