IBM Websphere Application Server Liberty
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Websphere Application Server Liberty.
By the Year
In 2026 there have been 28 vulnerabilities in IBM Websphere Application Server Liberty with an average score of 7.1 out of ten. Websphere Application Server Liberty did not have any published security vulnerabilities last year. That is, 28 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 28 | 7.09 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 9.80 |
It may take a day or so for new Websphere Application Server Liberty vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Websphere Application Server Liberty Security Vulnerabilities
IBM WebSphere AppServer 8.5/9.0 ORB flaw permits arbitrary class loading via IIOP
CVE-2026-8400
8.1 - High
- August 05, 2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
Reflection Injection
IBM WAS DoS via Crafted HTTP Request in 8.5-9.0 and Liberty 17-26
CVE-2026-9322
7.5 - High
- July 30, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
Resource Exhaustion
IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7 Bypass Security Constraints
CVE-2026-10842
7.5 - High
- July 30, 2026
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
Authentication Bypass by Alternate Name
IBM WAS Liberty 17.0.0.3 DoS via Crafty Request (Memory Exhaustion)
CVE-2026-11897
7.5 - High
- July 30, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Allocation of Resources Without Limits or Throttling
IBM WSA Liberty 17-26 CSRF SSRF via collectiveController
CVE-2026-14980
8.3 - High
- July 30, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
Improper Privilege Management
XSS CSRF in IBM WebSphere Liberty 17.0.0.3-26.0.0.8
CVE-2026-2482
3.1 - Low
- July 29, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Session Riding
IBM WSS/LIBERTY SIP SSRF via sipServlet-1.1 pre-26.0.0.9
CVE-2026-14529
9.4 - Critical
- July 29, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
Missing Authentication for Critical Function
IBM WebSphere Liberty RCE via collectiveCtrl-1.0 (v17.0.0.3-26.0.0.8)
CVE-2026-14976
7.1 - High
- July 28, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
Missing Authentication for Critical Function
IBM WebSphere WAS & Liberty DoS via HTTP Channel Unbounded Resource Allocation
CVE-2026-14981
7.5 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
Resource Exhaustion
IBM WebSphere App Server Liberty 17-26 DOS via Uncontrolled Heap Allocation
CVE-2026-15057
7.5 - High
- July 28, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
Memory Corruption
IBM WS HTTP Resp Smuggling via HTTP version token (pre 9.0/8.5, Liberty 17+)
CVE-2026-15064
8.7 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
HTTP Request Smuggling
IBM WAS Liberty 17.0.0.3-26.0.0.8 ND Collective Controller path-segment injection
CVE-2026-15280
7.5 - High
- July 28, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
Directory traversal
IBM WAS HTTP Request Smuggling via TRACE (8.5/9.0; Liberty 17-26)
CVE-2026-15325
8.7 - High
- July 28, 2026
IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
HTTP Request Smuggling
Request smuggling in IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7
CVE-2026-15328
7.4 - High
- July 28, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
HTTP Request Smuggling
IBM WebSphere Liberty 17.0.0.3-26.0.0.8 DS: restConnector-2.0 Feature
CVE-2026-16192
7.1 - High
- July 28, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
Stack Exhaustion
HTTP Req Smuggling in IBM WebSphere WSAS 8.5/9.0 & Liberty 17.0.0.3-26.0.0.6
CVE-2026-11541
7.4 - High
- June 30, 2026
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
HTTP Request Smuggling
CVE-2026-11546: SSRF in IBM WAS Liberty 17.0.0.326.0.0.7 (adminCenter1.0)
CVE-2026-11546
7.1 - High
- June 30, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.
SSRF
SSRF in IBM WebSphere App Server Liberty 17.0.0.3-26.0.0.7 via apiDiscovery-1.0
CVE-2026-11714
8.5 - High
- June 30, 2026
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
SSRF
IBM WAS Liberty Arbitrary File Read via restConnector-2.0 (17.0.0.3-26.0.0.6)
CVE-2026-11806
7.2 - High
- June 30, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0 feature enabled.
HTTP Request Smuggling
IBM WebSphere App Server DoS: crafted request (pre 9.0/8.5, Liberty 1726)
CVE-2026-9320
5.9 - Medium
- June 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
WAS DoS via crafted request (8.59.0 & Liberty 17.026.0)
CVE-2026-9071
7.5 - High
- June 22, 2026
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
IBM WebSphere App Server 9.0/8.5/Liberty 17-26 HTTP Request Smuggling
CVE-2026-8646
7.4 - High
- June 22, 2026
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a specially crafted request to the application server thereby allowing the attacker to bypass security controls, spoof identity, escalate privilege, and expose sensitive information.
HTTP Request Smuggling
Timing-Window Security Bypass in IBM WSAS Liberty 22.0.0.11-26.0.0.5
CVE-2026-5516
4.4 - Medium
- May 27, 2026
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions by exploiting a specific timing window.
Race Condition
IBM WebSphere App Server Liberty DoS via crafted request (v19.0-26.0)
CVE-2026-4410
4.8 - Medium
- May 27, 2026
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
Resource Exhaustion
IBM WSA Liberty 17.0.0.326.0.0.4: NoAuth Identity Spoofing
CVE-2026-3621
7.5 - High
- April 22, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.
Improper Privilege Management
IBM WebSphere App Server Liberty 17.0.0.3-26.0.0.3 Admin Security Weakness
CVE-2025-14917
6.7 - Medium
- March 25, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
1393
Privilege Escalation in IBM WebSphere AppSrv Liberty 17.0.0.3-26.0.0.3
CVE-2025-14915
6.5 - Medium
- March 25, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty is affected by privilege escalation. A privileged user could gain additional access to the application server.
Information Disclosure
IBM WebSphere Liberty 17.0-26.0 weaker security via Security Util
CVE-2025-14923
4.7 - Medium
- March 03, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.
Use of Hard-coded Cryptographic Key
IBM WebSphere AS Liberty Weak Expiration Handling 23.0.0.9-10
CVE-2023-46158
9.8 - Critical
- October 25, 2023
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
Insufficient Session Expiration
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Websphere Application Server Liberty or by IBM? Click the Watch button to subscribe.