CVE-2026-15822
Received
Received - Intake
Denial of Service in IBM DataPower Gateway
Vulnerability report for CVE-2026-15822, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: IBM Corporation
Description
Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to improper memoization of GraphQL fragment spreads.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| IBM | DataPower | Gateway 10.6CD 10.6.1 |
| IBM | DataPower | Gateway 10.6.0 10.6.0.0 |
| IBM | DataPower | Gateway 11.0.0 11.0.0.0 |
| IBM | DataPower | Gateway 10.5.0 10.5.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-405 | The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric." |