CVE-2026-8620 Details
Description
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.
A vulnerability allowing HTTP request smuggling has been identified in the IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty, specifically in versions 8.5 and 9.0. This vulnerability arises from inconsistent interpretation of HTTP requests, which can be exploited through specially crafted requests.
Users are advised to apply the currently available Web Server Plug-ins interim fix or fix pack that contains the fix for APAR PH71342. For Web Server Plug-ins for IBM WebSphere Application Server V9.0.0.0 through 9.0.5.27, upgrade to the required minimal fix pack level and then apply the interim fix for PH71342, or upgrade to Web Server Plug-ins Fix Pack 9.0.5.28 or later. For V8.5.0.0 through 8.5.5.29, follow the same interim fix procedure or upgrade to Web Server Plug-ins Fix Pack 8.5.5.30 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7274072 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5.0.0, < 8.5.5.30 >= 9.0.0.0, < 9.0.5.28 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 26, 2026 | New CVE Received | [email protected] |