CVE-2026-8856
published 2026-05-26CVE-2026-8856: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
PriorityP349critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.20%
9.6th percentile
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | http_server | — | — |
| ibm | http_server | 8.5.0 – Interim Fix 002 | — |
| ibm | http_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | http_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48g8-mw8p-w6j7: IBM HTTP Server 8
ghsa_unreviewed·2026-05-26
CVE-2026-8856 [HIGH] CWE-400 GHSA-48g8-mw8p-w6j7: IBM HTTP Server 8
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
VulDB
IBM HTTP Server up to 9.0 resource consumption
vuldb·2026-05-26·CVSS 9.1
CVE-2026-8856 [CRITICAL] IBM HTTP Server up to 9.0 resource consumption
A vulnerability has been found in IBM HTTP Server up to 9.0 and classified as problematic. This impacts an unknown function. Performing a manipulation results in resource consumption.
This vulnerability is identified as CVE-2026-8856. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published