SB2026100106 - Multiple vulnerabilities in IBM App Connect Enterprise



SB2026100106 - Multiple vulnerabilities in IBM App Connect Enterprise

Published: October 1, 2026 Updated: October 1, 2026

Security Bulletin ID SB2026100106
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 12
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 12 vulnerabilities.


1) CRLF injection (CVE-ID: CVE-2026-1527)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary HTTP headers and smuggle raw data to non-HTTP services.

The vulnerability exists due to improper neutralization of CRLF sequences in the upgrade option of client.request() when processing user-controlled input. A remote attacker can supply a specially crafted upgrade value to inject arbitrary HTTP headers and smuggle raw data to non-HTTP services.

User interaction is required because an application must pass user-controlled input to the upgrade option.


2) Interpretation Conflict (CVE-ID: CVE-2026-92597)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an interpretation conflict in the Nodemailer address parser when processing a recipient address containing an RFC 5322 comment. A remote attacker can submit a crafted recipient address to disclose sensitive information.

Exploitation requires an application domain check that interprets the address differently from Nodemailer, such as a strict parser whose parse defects are not inspected or a prefix or substring allow-list check.


3) Use of Web Browser Cache Containing Sensitive Information (CVE-ID: CVE-2026-13697)

CWE-ID: CWE-525 - Use of Web Browser Cache Containing Sensitive Information

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper cache handling in the cache interceptor when processing malformed qualified Cache-Control private directives in shared cache mode. A remote attacker can cause an upstream response with a malformed private directive to be stored in the shared cache and served to a later caller with the same cache key to disclose sensitive information.

Exploitation requires shared cache mode, a later request matching the same cache key, and no separating Vary header.


4) Interpretation Conflict (CVE-ID: CVE-2026-14643)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to interpretation conflict in the cache interceptor when processing Cache-Control directives with optional whitespace around the = character. A remote attacker can send requests that cause authenticated responses to be stored and later served to another caller to disclose sensitive information.

Only applications that explicitly enable shared cache mode, forward Authorization headers upstream, and receive cacheable responses with qualified private or no-cache directives are vulnerable.


5) Use of cache containing sensitive information (CVE-ID: CVE-2026-9678)

CWE-ID: CWE-524 - Use of Cache Containing Sensitive Information

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of cache containing sensitive information in the cache interceptor when processing responses with whitespace-padded qualified private or no-cache directives in the Cache-Control header. A remote attacker can send requests that resolve to the same cache key to disclose sensitive information.

Only applications that explicitly enable interceptors.cache() in shared-cache mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified directives are vulnerable.


6) CRLF injection (CVE-ID: CVE-2026-15157)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary HTTP headers and potentially smuggle a second request past the upstream.

The vulnerability exists due to improper neutralization of CRLF sequences in lib/dispatcher/client-h1.js when processing a duck-typed blob-like body with an untrusted .type property through the HTTP/1.1 dispatcher. A remote attacker can supply crafted CRLF sequences in the .type value to inject arbitrary HTTP headers and potentially smuggle a second request past the upstream.

User interaction is required because exploitation occurs when an application passes untrusted input into a blob-like body's .type property. Native Blob is not affected, and fetch() is unaffected.


7) CRLF injection (CVE-ID: CVE-2022-35948)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject arbitrary data in server response.

The vulnerability exists due to insufficient validation of unsanitized input passed as request headers. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.


8) Interpretation Conflict (CVE-ID: CVE-2026-92598)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an interpretation conflict in the _normalizeAddress function in lib/mime-node/index.js when processing internationalized recipient domains. A remote attacker can submit a crafted recipient address that bypasses a domain allow-list to disclose sensitive information.

An invisible soft hyphen can trigger the domain-normalization discrepancy.


9) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-16728)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause downstream response desynchronization, connection hangs, or response corruption.

The vulnerability exists due to inconsistent interpretation of HTTP response framing in interceptors.retry() when retrying or resuming a partial upstream response. A remote attacker can send a partial response with mismatched framing headers to cause downstream response desynchronization, connection hangs, or response corruption.

The issue requires interceptors.retry() to be enabled and a downstream forwarder that forwards upstream headers and bodies without removing or recalculating Content-Length.


10) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-16729)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass cookie security protections and modify cookie attributes.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the setCookie function when processing user-controlled domain or unparsed setCookie fields. A remote attacker can supply crafted input containing cookie attributes to bypass cookie security protections and modify cookie attributes.

Exploitation requires an application to pass user-controlled input to these fields, such as in multi-tenant or reverse-proxy deployments.


11) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-92595)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose arbitrary local files and perform server-side request forgery.

The vulnerability exists due to improper access control in the MailMessage.resolveContent() public API when resolving attacker-influenced message content through the legacy signature. A remote user can supply message content that references local file paths or internal URLs to disclose arbitrary local files and perform server-side request forgery.

The issue is reachable when disableFileAccess or disableUrlAccess is enabled and application code or a plugin invokes the documented legacy API without an options argument.


12) Inefficient Algorithmic Complexity (CVE-ID: CVE-2026-92596)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in the addressparser result accumulator when parsing a crafted comma-separated address list. A remote attacker can provide a crafted address value to cause a denial of service.

The issue occurs on the library's default code path and requires no special application configuration or cooperating receiver.


Remediation

Install update from vendor's website.