CVE-2026-15328
Received Received - Intake

HTTP Request Smuggling in IBM WebSphere Application Server

Vulnerability report for CVE-2026-15328, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: IBM Corporation

Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server 9.0
ibm websphere_application_server 8.5
ibm websphere_application_server_liberty From 17.0.0.3 (inc) to 26.0.0.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM WebSphere Application Server versions 9.0, 8.5, and Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to HTTP request smuggling. This means attackers can send specially crafted requests that get interpreted differently by front-end and back-end servers, potentially bypassing security controls or accessing unauthorized data.

Detection Guidance

HTTP request smuggling vulnerabilities like CVE-2026-15328 can be detected by analyzing HTTP request parsing inconsistencies. Use tools like Burp Suite, OWASP ZAP, or curl to send malformed requests and observe backend server responses for discrepancies. Monitor for unusual patterns in request headers such as Content-Length and Transfer-Encoding.

Impact Analysis

This vulnerability could allow attackers to smuggle malicious HTTP requests, leading to unauthorized access to sensitive data, session hijacking, or bypassing security mechanisms. It may also enable cache poisoning or other attacks that disrupt service availability.

Compliance Impact

This vulnerability could lead to unauthorized data access or breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed due to the HTTP request smuggling flaw.

Mitigation Strategies

Update IBM WebSphere Application Server 9.0, 8.5, and Liberty 17.0.0.3 through 26.0.0.7 to the latest patched versions to address HTTP request smuggling vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15328. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart