CVE-2026-15064High· 8.7▾ TwilightIBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
websphere_application_server >= 8.5.0.0, < 8.5.5.31websphere_application_server >= 9.0.0.0, < 9.0.5.29websphere_application_server >= 17.0.0.3, < 26.0.0.8Upgrade past the affected range:
websphere_application_server 26.0.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15328High· 7.4IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling.
CVE-2026-14981High· 7.5IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
CVE-2026-11548Medium· 4.8IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-11710Medium· 6.5IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.
CVE-2026-11722Medium· 4.8IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.
CVE-2026-10841Medium· 4.2IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.