CVE-2026-8179
published 2026-05-27CVE-2026-8179: IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.40%
32.3th percentile
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aspera_high-speed_transfer_endpoint | — | — |
| ibm | aspera_high-speed_transfer_endpoint | 3.7.4 – 4.4.6 | — |
| ibm | aspera_high-speed_transfer_server | — | — |
| ibm | aspera_high-speed_transfer_server | 3.7.4 – 4.4.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Aspera High-Speed Transfer Endpoint up to 4.4.7 FP1 Asperahttpd stack-based overflow
vuldb·2026-05-27·CVSS 8.8
CVE-2026-8179 [HIGH] IBM Aspera High-Speed Transfer Endpoint up to 4.4.7 FP1 Asperahttpd stack-based overflow
A vulnerability classified as critical has been found in IBM Aspera High-Speed Transfer Endpoint and Aspera High-Speed Transfer Server up to 4.4.7 FP1. This vulnerability affects unknown code of the component Asperahttpd. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is known as CVE-2026-8179. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-mf5h-x3qw-xr56: IBM Aspera High-Speed Transfer Endpoint 3
ghsa_unreviewed·2026-05-27
CVE-2026-8179 [HIGH] CWE-121 GHSA-mf5h-x3qw-xr56: IBM Aspera High-Speed Transfer Endpoint 3
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published