CVE-2026-10841 PUBLISHED

Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.

Assigner: ibm
Reserved: 04.06.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.2

Product Status

Vendor IBM
Product CICS TX Advanced
Versions
  • Version 10.1 is affected

Solutions

IBM strongly recommends addressing the vulnerabilities now by downloading and applying the below fix. ProductVersionPlatformRemediation/FixIBM CICS TX Advanced10.1LinuxDownload and apply the update from Fix Central

References

Problem Types

  • CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE