What is CVE-2026-15064?
CVE-2026-15064 is an HTTP Response Smuggling vulnerability in IBM WebSphere Application Server (traditional 8.5, 9.0) and Liberty (versions 17.0.0.3 through 26.0.0.7), caused by improper handling of non-standard HTTP version tokens. This can allow attackers to manipulate HTTP traffic. Affected systems should be patched immediately with the updates provided by IBM.
Azərbaycanca: CVE-2026-15064, IBM WebSphere Application Server (ənənəvi 8.5, 9.0 versiyaları) və Liberty (17.0.0.3-26.0.0.7) serverlərində HTTP Cavab Qaçaqlaması (HTTP Response Smuggling) zəifliyidir. Bu problem qeyri-standart HTTP versiya tokenlərinin düzgün işlənməməsi səbəbindən yaranır. Təsirlənmiş sistemlərdə dərhal IBM tərəfindən təqdim olunan təhlükəsizlik yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Which versions of IBM WebSphere are affected by CVE-2026-15064?
The vulnerability affects IBM WebSphere Application Server traditional versions 8.5 and 9.0, as well as Liberty versions 17.0.0.3 through 26.0.0.7.
What is the root cause of the CVE-2026-15064 vulnerability?
This HTTP Response Smuggling vulnerability is caused by improper handling of non-standard HTTP version tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.