SB2026100104 - Multiple vulnerabilities in IBM DataPower Gateway



SB2026100104 - Multiple vulnerabilities in IBM DataPower Gateway

Published: October 1, 2026 Updated: October 1, 2026

Security Bulletin ID SB2026100104
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-55968)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity and allocation of resources without limits or throttling in Node.js server receive transports when processing input. A remote attacker can send specially crafted input to cause a denial of service.


2) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-48144)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to impersonate a trusted server.

The vulnerability exists due to improper validation of certificate with host mismatch in the c_glib TLS client when establishing TLS connections. A remote attacker can present a certificate for a different host to impersonate a trusted server.


3) Improper validation of certificate with host mismatch (CVE-ID: CVE-2026-48145)

CWE-ID: CWE-297 - Improper Validation of Certificate with Host Mismatch

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass hostname verification.

The vulnerability exists due to improper validation of certificate with host mismatch in the C++ TSSLSocket matchName() function when validating wildcard certificate names during TLS certificate verification. A remote attacker can present a crafted certificate with a mismatched hostname to bypass hostname verification.


4) Out-of-bounds read (CVE-ID: CVE-2026-55970)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in THeaderTransport::readHeaderFormat() when parsing input. A remote attacker can send specially crafted input to disclose sensitive information.


5) Out-of-bounds read (CVE-ID: CVE-2026-58662)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in the C++ THeaderTransport::readString() function when parsing input. A remote attacker can send specially crafted input to disclose sensitive information.


6) Improper access control (CVE-ID: CVE-2026-43870)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass origin validation.

The vulnerability exists due to improper access control in Node.js web_server.js when handling cross-origin requests. A remote attacker can send a specially crafted request to bypass origin validation.


7) Mismatched Memory Management Routines (CVE-ID: CVE-2025-48431)

CWE-ID: CWE-762 - Mismatched Memory Management Routines

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to mismatched memory management routines in c_glib language bindings when handling specially crafted requests. A remote attacker can send a specially crafted request to cause a denial of service.

The issue can terminate a c_glib-based Thrift server with a fatal "free(): invalid pointer" error.


8) Integer overflow (CVE-ID: CVE-2026-41602)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow or wraparound in the TFramedTransport Go language implementation when parsing framed transport data. A remote attacker can send specially crafted framed input to cause a denial of service.


9) Uncontrolled Recursion (CVE-ID: CVE-2026-41606)

CWE-ID: CWE-674 - Uncontrolled Recursion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled recursion in c_glib dispatch when processing crafted input. A remote attacker can send crafted input to cause a denial of service.


10) Out-of-bounds read (CVE-ID: CVE-2026-41607)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the C++ JSON parser when parsing input. A remote attacker can send specially crafted input to disclose sensitive information.


11) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-43868)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory allocation with excessive size value in the Rust implementation when parsing input. A remote attacker can send specially crafted input to cause a denial of service.


Remediation

Install update from vendor's website.