CVE-2026-8850
IBM HTTP Server mod_ibm_upload Denial of Service
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | http_server | to 8.5.5.30 (inc) |
| ibm | http_server | to 9.0.5.29 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability affects the availability of the IBM HTTP Server by allowing a denial of service (DoS) attack through the mod_ibm_upload module. It does not impact confidentiality or integrity of data.
Since the vulnerability only impacts availability and does not compromise data confidentiality or integrity, its direct effect on compliance with standards like GDPR or HIPAAβwhich primarily focus on protecting personal data privacy and integrityβis limited.
However, availability is also a component of many compliance frameworks, so prolonged denial of service could potentially affect compliance if it disrupts critical services or access to protected data.
Can you explain this vulnerability to me?
CVE-2026-8850 is a vulnerability in the IBM HTTP Server (versions 8.5 and 9.0) that allows an attacker to cause a denial of service (DoS) via the optional module mod_ibm_upload.
The issue is caused by a NULL pointer dereference, which can cause the server to crash or become unresponsive.
The attack can be performed remotely over the network without requiring any privileges or user interaction.
How can this vulnerability impact me? :
This vulnerability impacts the availability of the IBM HTTP Server by allowing an attacker to cause the server to crash or become unresponsive, resulting in a denial of service.
It does not affect the confidentiality or integrity of the data handled by the server.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the CVE-2026-8850 vulnerability in IBM HTTP Server, IBM recommends applying the interim fix for APAR PH71265.
Alternatively, you can upgrade to Fix Pack 9.0.5.29 or later for version 9.0, or Fix Pack 8.5.5.30 or later for version 8.5.