CVE-2026-8175: Multiple vulnerabilities in Aspera applications.
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.
Other sources
IBM Aspera High-Speed Transfer Server and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8175?
CVE-2026-8175 has a critical severity rating of 9.8.
What type of vulnerability is CVE-2026-8175?
CVE-2026-8175 is a buffer overflow vulnerability in the asperahttpd component.
How do I fix CVE-2026-8175?
To fix CVE-2026-8175, upgrade to IBM Aspera High-Speed Transfer Server or Endpoint version 4.4.7 Fix Pack 2.
Which versions are affected by CVE-2026-8175?
CVE-2026-8175 affects IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1.
What could happen if CVE-2026-8175 is exploited?
Exploitation of CVE-2026-8175 could lead to a denial-of-service or unauthorized access due to the buffer overflow.