CVE-2026-9071
Undergoing Analysis Undergoing Analysis - In Progress
Denial of Service in IBM WebSphere Application Server

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: IBM Corporation

Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server 9.0
ibm websphere_application_server 8.5
ibm websphere_application_server_liberty From 17.0.0.3 (inc) to 26.0.0.6 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects IBM WebSphere Application Server versions 9.0, 8.5, and IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.6. It is a denial of service vulnerability caused by sending a specially-crafted request to the server.

A remote attacker can exploit this vulnerability to cause the server to consume excessive memory resources, potentially leading to service disruption.

Impact Analysis

Exploitation of this vulnerability can lead to a denial of service condition on the affected IBM WebSphere Application Server. This means the server may become unresponsive or crash due to excessive memory consumption triggered by a specially-crafted request from a remote attacker.

As a result, legitimate users may be unable to access services hosted on the server, causing potential downtime and disruption of business operations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart