CVE-2026-15057
published 2026-07-28CVE-2026-15057: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.46%
37.4th percentile
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | >= 17.0.0.3 < 26.0.0.8 | 26.0.0.8 |
| ibm | websphere_application_server_liberty | 17.0.0.3 – 26.0.0.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM WebSphere Application Server up to 26.0.0.7 denial of service (EUVD-2026-50025)
vuldb·2026-07-28·CVSS 7.5
CVE-2026-15057 [HIGH] IBM WebSphere Application Server up to 26.0.0.7 denial of service (EUVD-2026-50025)
A vulnerability was found in IBM WebSphere Application Server up to 26.0.0.7 and classified as problematic. This affects an unknown function. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-15057. The attack can be executed remotely. There is not any exploit available.
GHSA
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
ghsa_unreviewed·2026-07-28
CVE-2026-15057 [HIGH] CWE-787 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-28
Published