SB2026100604 - Multiple vulnerabilities in IBM webMethods Developer Portal and IBM webMethods ControlPlane



SB2026100604 - Multiple vulnerabilities in IBM webMethods Developer Portal and IBM webMethods ControlPlane

Published: October 6, 2026

Security Bulletin ID SB2026100604
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 90% Low 10%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-56745)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in the SpdyHttpDecoder handler when processing a client-initiated SYN_STREAM frame followed by an RST_STREAM frame or oversized content. A remote attacker can send crafted SPDY frames to cause a denial of service.

The issue leaks a pooled ByteBuf by removing the partially constructed FullHttpRequest from an internal map without releasing the underlying buffer.


2) Improper access control (CVE-ID: CVE-2026-56746)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to a logical operator error in the origin evaluation process. A remote attacker can send a specially crafted request to bypass the short-circuit mechanism.


3) Infinite loop (CVE-ID: CVE-2026-59901)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in Bzip2BlockDecompressor.read() when parsing a malformed bzip2 stream. A remote attacker can send a specially crafted compressed stream to cause a denial of service.

The issue can permanently capture the event-loop thread in an infinite loop.


4) Input validation error (CVE-ID: CVE-2026-59898)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform HTTP request smuggling and protocol-confusion attacks.

The vulnerability exists due to improper input validation in the WebSockets V07/V08 handshaker when handling WebSocket upgrade requests. A remote attacker can send a specially crafted request with Sec-WebSocket-Version: 7 while omitting Connection: Upgrade and Upgrade: websocket headers to perform HTTP request smuggling and protocol-confusion attacks.

The issue affects protocol switching behavior in cases where an intermediary proxy would not recognize the request as a WebSocket upgrade.


5) Resource exhaustion (CVE-ID: CVE-2026-55831)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in DefaultSpdySettingsFrame settings map handling when processing a crafted SPDY/3.1 SETTINGS frame. A remote attacker can send a specially crafted SETTINGS frame to cause a denial of service.

Exploitation requires the target to accept SPDY/3.1 traffic through a Netty pipeline containing SpdyFrameCodec.


6) Input validation error (CVE-ID: CVE-2026-55833)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the SPDY header decoder in SpdyFrameCodec when processing zlib-compressed SPDY header blocks after maxHeaderSize truncation. A remote attacker can send a specially crafted HEADERS frame to cause a denial of service.

Exploitation requires a reachable SPDY pipeline using SpdyFrameCodec and a decoder path that selects the zlib decoder.


7) Input validation error (CVE-ID: CVE-2026-59900)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass request routing controls.

The vulnerability exists due to improper input validation in Http2StreamFrameToHttpObjectCodec and InboundHttp2ToHttpAdapter when translating HTTP/2 HEADERS frames containing both the :authority pseudo-header and a literal host header. A remote attacker can send a specially crafted HTTP/2 request to bypass request routing controls.

The issue occurs because the translator maps :authority to Host and separately copies the literal host header, resulting in an HttpRequest object with two Host headers containing different attacker-controlled values.


8) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-59899)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in HttpContentEncoder when processing pipelined HTTP/1.1 requests. A remote attacker can send a flood of crafted requests faster than the application produces responses to cause a denial of service.

The issue affects the per-channel acceptEncodingQueue, which accumulates attacker-controlled data on the I/O thread and is drained only when the application writes a non-1xx response.


9) CRLF injection (CVE-ID: CVE-2026-59921)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject arbitrary MIME headers into multipart request parts.

The vulnerability exists due to improper neutralization of CRLF sequences in io.netty.handler.codec.http.multipart.HttpPostRequestEncoder when constructing multipart HTTP request bodies using user-controlled filenames or field names. A remote user can supply a specially crafted filename or form field name to inject arbitrary MIME headers into multipart request parts.

Exploitation requires application use of the multipart encoder with user-controlled filename or field name data that is forwarded without sanitization.


10) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-73508)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing release of resource after rffective lifetime in DNS Record Decoder. A remote attacker can cause a denial of service condition on the target system.


Remediation

Install update from vendor's website.