SB2026100604 - Multiple vulnerabilities in IBM webMethods Developer Portal and IBM webMethods ControlPlane
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-56745)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the SpdyHttpDecoder handler when processing a client-initiated SYN_STREAM frame followed by an RST_STREAM frame or oversized content. A remote attacker can send crafted SPDY frames to cause a denial of service.
The issue leaks a pooled ByteBuf by removing the partially constructed FullHttpRequest from an internal map without releasing the underlying buffer.
2) Improper access control (CVE-ID: CVE-2026-56746)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a logical operator error in the origin evaluation process. A remote attacker can send a specially crafted request to bypass the short-circuit mechanism.
3) Infinite loop (CVE-ID: CVE-2026-59901)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in Bzip2BlockDecompressor.read() when parsing a malformed bzip2 stream. A remote attacker can send a specially crafted compressed stream to cause a denial of service.
The issue can permanently capture the event-loop thread in an infinite loop.
4) Input validation error (CVE-ID: CVE-2026-59898)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform HTTP request smuggling and protocol-confusion attacks.
The vulnerability exists due to improper input validation in the WebSockets V07/V08 handshaker when handling WebSocket upgrade requests. A remote attacker can send a specially crafted request with Sec-WebSocket-Version: 7 while omitting Connection: Upgrade and Upgrade: websocket headers to perform HTTP request smuggling and protocol-confusion attacks.
The issue affects protocol switching behavior in cases where an intermediary proxy would not recognize the request as a WebSocket upgrade.
5) Resource exhaustion (CVE-ID: CVE-2026-55831)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in DefaultSpdySettingsFrame settings map handling when processing a crafted SPDY/3.1 SETTINGS frame. A remote attacker can send a specially crafted SETTINGS frame to cause a denial of service.
Exploitation requires the target to accept SPDY/3.1 traffic through a Netty pipeline containing SpdyFrameCodec.
6) Input validation error (CVE-ID: CVE-2026-55833)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the SPDY header decoder in SpdyFrameCodec when processing zlib-compressed SPDY header blocks after maxHeaderSize truncation. A remote attacker can send a specially crafted HEADERS frame to cause a denial of service.
Exploitation requires a reachable SPDY pipeline using SpdyFrameCodec and a decoder path that selects the zlib decoder.
7) Input validation error (CVE-ID: CVE-2026-59900)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass request routing controls.
The vulnerability exists due to improper input validation in Http2StreamFrameToHttpObjectCodec and InboundHttp2ToHttpAdapter when translating HTTP/2 HEADERS frames containing both the :authority pseudo-header and a literal host header. A remote attacker can send a specially crafted HTTP/2 request to bypass request routing controls.
The issue occurs because the translator maps :authority to Host and separately copies the literal host header, resulting in an HttpRequest object with two Host headers containing different attacker-controlled values.
8) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-59899)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in HttpContentEncoder when processing pipelined HTTP/1.1 requests. A remote attacker can send a flood of crafted requests faster than the application produces responses to cause a denial of service.
The issue affects the per-channel acceptEncodingQueue, which accumulates attacker-controlled data on the I/O thread and is drained only when the application writes a non-1xx response.
9) CRLF injection (CVE-ID: CVE-2026-59921)
CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject arbitrary MIME headers into multipart request parts.
The vulnerability exists due to improper neutralization of CRLF sequences in io.netty.handler.codec.http.multipart.HttpPostRequestEncoder when constructing multipart HTTP request bodies using user-controlled filenames or field names. A remote user can supply a specially crafted filename or form field name to inject arbitrary MIME headers into multipart request parts.
Exploitation requires application use of the multipart encoder with user-controlled filename or field name data that is forwarded without sanitization.
10) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-73508)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to missing release of resource after rffective lifetime in DNS Record Decoder. A remote attacker can cause a denial of service condition on the target system.
Remediation
Install update from vendor's website.