CVE-2026-10852
Awaiting Analysis
Awaiting Analysis - Queue
Denial of Service in IBM WebSphere WebServer Plug-in
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: IBM Corporation
Description
Description
IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | websphere_application_server | From 7.3 (inc) to 7.6 (inc) |
| ibm | websphere_application_server_liberty | From 7.3 (inc) to 7.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |