
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11710 is an HTTP request smuggling vulnerability in IBM WebSphere Application Server (WAS) 8.5, caused by improper handling of Content-Length headers. It was published on September 18, 2026, and is classified under CWE-444 (Inconsistent Interpretation of HTTP Requests). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, IBM Advisory).
The root cause is improper handling of Content-Length headers in IBM WebSphere Application Server 8.5, classified as CWE-444 (HTTP Request Smuggling / CAPEC-33). An unauthenticated remote attacker can craft malicious HTTP requests that exploit inconsistencies in how the WAS intermediary and backend servers parse Content-Length values, causing the backend to interpret smuggled request boundaries differently than the front-end proxy. This allows the attacker to inject or prepend content to subsequent requests processed by the server, potentially bypassing security controls. No public proof-of-concept code has been identified at this time (GitHub Advisory, IBM Advisory).
Successful exploitation could allow an unauthenticated network attacker to bypass authentication and authorization controls, access sensitive data (high confidentiality impact), and perform limited data modification (low integrity impact). Availability is not directly affected. In multi-tier deployments where WAS acts as an intermediary, smuggled requests could be used to poison shared connection queues, potentially affecting other users' sessions or enabling further lateral movement within the application environment (GitHub Advisory, Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The NVD SSVC assessment indicates exploitation is "none" and the attack is not automatable, reflecting the high attack complexity required. The EPSS score is approximately 0.228% (12th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Advisory).
Content-Length headers targeting WAS 8.5 endpoints; unexpected HTTP/1.1 keep-alive connections with anomalous body lengths.IBM has released a security patch addressing this vulnerability, referenced in the IBM support page (node/7286731); administrators should apply this patch immediately (IBM Advisory). As a workaround, organizations should implement strict HTTP request validation and Content-Length header verification at the network perimeter or via a Web Application Firewall (WAF) to detect and block malformed requests. Disabling HTTP/1.1 keep-alive connections or enforcing strict request parsing at the proxy layer can also reduce exposure (GitHub Advisory).
IBM published a security bulletin specifically addressing WAS shipped with Jazz Service Management (JazzSM), indicating the vulnerability has broader product impact beyond standalone WAS deployments (IBM JazzSM Bulletin). Coverage has been limited to automated vulnerability tracking platforms and IBM's own advisory channels, with no notable independent researcher commentary or significant social media discussion identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."