CVE-2026-9071: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Other sources
IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.7 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71370 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71631
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9071?
CVE-2026-9071 has a high severity rating of 7.5.
What is the risk associated with CVE-2026-9071?
The risk associated with CVE-2026-9071 is rated at 31.
How do I fix CVE-2026-9071?
To fix CVE-2026-9071, upgrade your IBM WebSphere Application Server or WebSphere Application Server - Liberty to a version that addresses this vulnerability.
What types of servers are affected by CVE-2026-9071?
CVE-2026-9071 affects IBM WebSphere Application Server versions 9.0 and 8.5, as well as IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.6.
What type of attack does CVE-2026-9071 enable?
CVE-2026-9071 enables a denial of service attack due to uncontrolled resource consumption.