CVE-2026-9002 Details
Description
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow an attacker on the same network to trigger a StackOverflowError or OutOfMemoryError, resulting in a crash of the WebSphere Application Server JVM.
A denial-of-service vulnerability has been identified in IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6. The issue arises from improper validation in the XDF decoder, which allows an adjacent attacker to cause resource exhaustion. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without adequate bounds checking. This could enable an attacker on the same network to trigger a StackOverflowError or OutOfMemoryError, leading to a crash of the WebSphere Application Server JVM.
Users can upgrade to the latest fixpack 8.6.1.6 and then apply the PH71946 iFix. For those already using 8.6.1.6, the PH71946 iFix can be applied directly.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7278346 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere extreme scale | >= 8.6.1.0, <= 8.6.1.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | New CVE Received | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |