CVE-2026-4410: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a denial of service
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.6Patch APAR PH70807 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.30Patch APAR PH70807 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.28Patch APAR PH70807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH70616 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH70807
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4410?
CVE-2026-4410 has a medium severity rating of 4.8.
How do I fix CVE-2026-4410?
To fix CVE-2026-4410, apply the interim fix or fix pack that addresses APAR PH70807 and APAR PH70616.
What type of vulnerability is CVE-2026-4410?
CVE-2026-4410 is a denial of service vulnerability affecting IBM WebSphere Application Server and Liberty.
Which versions are affected by CVE-2026-4410?
CVE-2026-4410 affects IBM WebSphere Application Server versions 9.0, 8.5, and Liberty versions 19.0.0.7 through 26.0.0.5.
Who can exploit CVE-2026-4410?
A remote attacker can exploit CVE-2026-4410 by sending a specially-crafted request to the affected software.