Inconsistent interpretation of HTTP requests in IBM WebSphere Application Server Liberty - CVE-2026-11806
Published: July 10, 2026
Vulnerability details
The vulnerability allows a remote privileged user to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests with the restConnector-2.0 feature enabled. A remote privileged user can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Enterprise Application Runtimes
PowerVM NovaLink
WebSphere Hybrid Edition
Cloud Pak for Applications
IBM Cloud Pak System
IBM SPSS Analytic Server
IBM TXSeries for Multiplatforms
How to mitigate CVE-2026-11806
PowerVM NovaLink - addressed in versions 2.2.1.1-260708, 2.3.3-260714
IBM TXSeries for Multiplatforms - update to 11.1.0.0 ifix22
External References
Related Security Bulletins
- Inconsistent interpretation of HTTP requests in IBM WebSphere Application Server - Liberty
- Inconsistent interpretation of HTTP requests in IBM Cloud Pak for Applications
- Inconsistent interpretation of HTTP requests in IBM Enterprise Application Runtimes
- Inconsistent interpretation of HTTP requests in IBM WebSphere Hybrid Edition
- Multiple vulnerabilities in IBM PowerVM Novalink
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in IBM TXSeries for Multiplatforms
- Inconsistent interpretation of HTTP requests in IBM Cloud Pak System