Inconsistent interpretation of HTTP requests in IBM WebSphere Application Server Liberty - CVE-2026-11806

 

Inconsistent interpretation of HTTP requests in IBM WebSphere Application Server Liberty - CVE-2026-11806

Published: July 10, 2026


Vulnerability identifier: #VU137316
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11806
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests with the restConnector-2.0 feature enabled. A remote privileged user can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

IBM WebSphere Application Server Liberty
Enterprise Application Runtimes
PowerVM NovaLink
WebSphere Hybrid Edition
Cloud Pak for Applications
IBM Cloud Pak System
IBM SPSS Analytic Server
IBM TXSeries for Multiplatforms

How to mitigate CVE-2026-11806

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 26.0.0.7
PowerVM NovaLink - addressed in versions 2.2.1.1-260708, 2.3.3-260714
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix22

External References

Related Security Bulletins