CVE-2026-9322 Details
Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
A denial-of-service vulnerability has been identified in IBM WebSphere Application Server versions 9.0 and 8.5, as well as in IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7. This vulnerability allows a remote attacker to cause uncontrolled resource consumption by sending a crafted HTTP request, leading to a degradation of service.
Users are advised to upgrade to the latest fix pack versions. For WebSphere Application Server Liberty, apply Fix Pack 26.0.0.8 or later. For WebSphere Application Server traditional, version 9.0.5.29 or later is recommended. For version 8.5, upgrade to 8.5.5.31 or later. Additional interim fixes may be available and linked off the interim fix download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7278576 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm websphere application server | >= 8.5.0.0, < 8.5.5.31 >= 9.0.0.0, < 9.0.5.29 >= 17.0.0.3, < 26.0.0.8 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jul 30, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |