CVE-2026-9170
published 2026-05-26CVE-2026-9170: IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.49%
38.8th percentile
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
| ibm | http_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q578-5vf7-89mr: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8
ghsa_unreviewed·2026-05-26
CVE-2026-9170 [HIGH] CWE-444 GHSA-q578-5vf7-89mr: IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to improper input validation.
VulDB
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty request smuggling (EUVD-2026-31939)
vuldb·2026-05-26·CVSS 7.5
CVE-2026-9170 [HIGH] IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty request smuggling (EUVD-2026-31939)
A vulnerability was found in IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5/9.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in http request smuggling.
This vulnerability is reported as CVE-2026-9170. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-26
Published