CVE-2026-8180 Details
Description
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.
A denial-of-service vulnerability has been identified in the asperahttpd component of IBM Aspera High-Speed Transfer Endpoint and IBM Aspera High-Speed Transfer Server, both versions 3.7.4 prior to 4.4.7 Fix Pack 1. An unauthenticated user can cause the asperahttpd service to crash, leading to a service disruption.
Users can upgrade to IBM Aspera High-Speed Transfer Server or Endpoint version 4.4.7 Fix Pack 2. Instructions for downloading this version are available on the IBM Support Fix Central website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7273615 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm aspera high-speed transfer endpoint | >= 3.7.4, <= 4.4.6 4.4.7 - 4.4.7 fixpack1 |
CPE
Remediation
| |
| ibm aspera high-speed transfer server | >= 3.7.4, <= 4.4.6 4.4.7 - 4.4.7 fixpack1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | [email protected] |