What is CVE-2026-15325?
CVE-2026-15325 is an HTTP request smuggling vulnerability in IBM WebSphere Application Server (versions 8.5, 9.0) and Liberty (versions 17.0.0.3 through 26.0.0.7) caused by improper handling of TRACE requests. This flaw could allow an attacker to bypass security controls by manipulating the content of HTTP requests. Affected systems should apply the security updates provided by IBM to mitigate this vulnerability.
Azərbaycanca: CVE-2026-15325, IBM WebSphere Application Server (ənənəvi 8.5, 9.0 versiyaları) və Liberty (17.0.0.3-dən 26.0.0.7-dək) proqramlarında TRACE sorğularının düzgün işlənməməsi səbəbindən HTTP request smuggling zəifliyidir. Bu, təcavüzkara HTTP sorğularının məzmununu manipulyasiya edərək təhlükəsizlik mexanizmlərindən yan keçməyə imkan verə bilər. Təsirə məruz qalan sistemlərdə bu zəifliyi aradan qaldırmaq üçün IBM tərəfindən təqdim olunan təhlükəsizlik yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Which versions of IBM WebSphere Application Server are affected by CVE-2026-15325?
CVE-2026-15325 affects IBM WebSphere Application Server traditional versions 8.5 and 9.0, as well as Liberty versions 17.0.0.3 through 26.0.0.7.
What can an attacker achieve by exploiting CVE-2026-15325?
By exploiting this HTTP request smuggling vulnerability, an attacker can bypass security controls by manipulating the content of HTTP requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.