Known vulnerabilities in IBM HTTP Server

Software CPE: cpe:2.3:a:ibm_corporation:ibm_http_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 58
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM HTTP Server IBM HTTP Server is affected by 58 known vulnerabilities: 1 critical, 10 high, 36 medium, 11 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129540 - Out-of-bounds read
CVE-2026-34059
CWE-125 Medium
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 24 more
#VU129541 - Out-of-bounds read
CVE-2026-34032
CWE-125 Medium
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 24 more
#VU129542 - Out-of-bounds read
CVE-2026-33857
CWE-125 Medium
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 24 more
#VU129543 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-33523
CWE-113 Medium
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 18 more
#VU129548 - Heap-based Buffer Overflow
CVE-2026-28780
CWE-122 High
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051101
and 24 more
#VU129549 - Improper Access Control
CVE-2026-24072
CWE-284 Low
No
No
8.5.5.30, 9.0.5.28 04.05.2026 SB2026050479
SB2026050772
SB2026051240
and 18 more
#VU128246 - Insufficient Entropy
CVE-2026-41080
CWE-331 Low
No
No
8.5.5.30, 9.0.5.28 27.04.2026 SB20260427193
SB2026051240
SB2026051270
and 13 more
#VU124278 - NULL Pointer Dereference
CVE-2026-32778
CWE-476 Low
No
No
8.5.5.30, 9.0.5.28 24.03.2026 SB2026032435
SB2026033028
SB2026033199
and 13 more
#VU124277 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-32777
CWE-835 Medium
No
No
8.5.5.30, 9.0.5.28 24.03.2026 SB2026032435
SB2026032436
SB2026032437
and 21 more
#VU124274 - NULL Pointer Dereference
CVE-2026-32776
CWE-476 Medium
No
No
8.5.5.30, 9.0.5.28 24.03.2026 SB2026032435
SB2026032765
SB2026033028
and 18 more
#VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
CVE-2025-58098
CWE-97 Low
Available
No
8.5.5.29, 9.0.5.27 04.12.2025 SB2025120441
SB2025121923
SB2025121940
and 46 more
#VU119148 - Server-Side Request Forgery (SSRF)
CVE-2025-59775
CWE-918 Medium
No
No
8.5.5.29, 9.0.5.27 04.12.2025 SB2025120441
SB2026010820
SB20260114117
and 10 more
#VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-65082
CWE-74 Low
No
No
8.5.5.29, 9.0.5.27 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 32 more
#VU119146 - Improper input validation
CVE-2025-66200
CWE-20 Low
No
No
8.5.5.29, 9.0.5.27 04.12.2025 SB2025120441
SB2025121923
SB2025122202
and 30 more
#VU115751 - Resource exhaustion
CVE-2025-59375
CWE-400 Medium
No
No
8.5.5.29, 9.0.5.27 17.09.2025 SB2025091783
SB2025091789
SB2025091790
and 106 more
#VU113185 - Expected Behavior Violation
CVE-2025-54090
CWE-440 Medium
No
No
9.0.5.25 23.07.2025 SB2025072350
SB2025080808
SB2025081113
and 9 more
#VU112734 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2024-42516
CWE-113 Low
No
No
8.5.5.29, 9.0.5.25 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 33 more
#VU112733 - Server-Side Request Forgery (SSRF)
CVE-2024-43204
CWE-918 Low
No
No
8.5.5.29, 9.0.5.25 10.07.2025 SB2025071040
SB2025071710
SB2025071764
and 27 more
#VU112732 - Server-Side Request Forgery (SSRF)
CVE-2024-43394
CWE-918 Medium
No
No
8.5.5.29, 9.0.5.25 10.07.2025 SB2025071040
SB2025071710
SB2025072111
and 7 more
#VU94503 - Server-Side Request Forgery (SSRF)
CVE-2024-40898
CWE-918 High
Available
No
8.5.5.27, 9.0.5.21 17.07.2024 SB20240717136
SB2024071896
SB2024081362
and 13 more


Showing elements 1 - 20 out of 58