CVE-2026-9002: WebSphere Extreme Scale Denial of Service via Improper Protocol Buffers Validation
IBM WebSphere Extreme Scale versions 8.6.1.0 through 8.6.1.6 contain a vulnerability that allows attackers on the same network to crash the application server. The flaw exists in how the system handles deeply nested Protocol Buffers messages without proper size limits, enabling an attacker to exploit this by sending specially crafted network packets that cause the Java Virtual Machine to run out of memory or exhaust the call stack, bringing down the service.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-400
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-02
NVD description (verbatim)
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow an attacker on the same network to trigger a StackOverflowError or OutOfMemoryError, resulting in a crash of the WebSphere Application Server JVM.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The XDF decoder in affected WebSphere Extreme Scale versions fails to validate bounds on Protocol Buffers message nesting depth and attacker-controlled length prefixes. When processing maliciously constructed serialized messages, the decoder recurses without limit or memory checks, triggering either a StackOverflowError (from unchecked recursion) or OutOfMemoryError (from unbounded buffer allocation). This results in unhandled exceptions that crash the JVM hosting the application server. The vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption) and requires network-adjacent access to exploit.
Business impact
An attacker with network access to the same segment can remotely crash WebSphere Extreme Scale instances, causing immediate service disruption. This is particularly significant for organizations using Extreme Scale as a distributed caching or data grid layer, as availability loss can cascade to dependent applications. Unlike vulnerabilities requiring authentication or user interaction, this requires only network proximity, lowering the barrier to exploitation and making it a practical denial-of-service vector in shared hosting or multi-tenant environments.
Affected systems
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 are affected. Organizations should inventory instances of these versions, particularly those deployed in network segments accessible to untrusted or less-trusted hosts. Verify exact version numbers via the application's administrative console or logs. Versions outside this range are unaffected; confirm your deployment version against IBM's product documentation.
Exploitability
Exploitability is straightforward: an attacker positioned on the same network segment can craft and transmit a malicious Protocol Buffers message without authentication or user interaction. The attack is repeatable and does not require social engineering. However, the attacker must have network access to reach the vulnerable service, which limits scope in well-segmented environments. The CVSS score of 6.5 (MEDIUM) reflects high availability impact but limited scope to adjacent networks and no confidentiality or integrity risk.
Remediation
Patch affected WebSphere Extreme Scale instances to a version outside the 8.6.1.0–8.6.1.6 range. Consult IBM's security bulletins for the specific patched version number. As an interim control, restrict network access to WebSphere Extreme Scale ports using firewalls or network segmentation, limiting exposure to trusted hosts and segments. Monitor for unexpected restarts or StackOverflowError/OutOfMemoryError events in JVM logs as indicators of exploitation attempts.
Patch guidance
IBM should have released a security patch addressing input validation in the XDF decoder. Obtain the patched version number from IBM's official security advisory or WebSphere Extreme Scale release notes. Test patches in a non-production environment first to confirm compatibility with your deployment. Apply patches to all affected instances, prioritizing systems in network-accessible environments. Restart services cleanly after patching to confirm stability.
Detection guidance
Monitor WebSphere Extreme Scale JVM logs for repeated StackOverflowError or OutOfMemoryError exceptions, particularly those correlating with unusual or high-frequency inbound network traffic. Network-based detection is challenging without protocol-level inspection, but anomalous resource spikes or unexpected service restarts are behavioral indicators. If WebSphere logs are centralized, set alerts for error conditions mentioning the XDF decoder or Protocol Buffers processing failures. Unexpected JVM heap exhaustion or unhandled exception crashes warrant investigation.
Why prioritize this
This vulnerability merits prompt attention if you operate WebSphere Extreme Scale in an environment where network access is not fully controlled. The combination of no authentication requirement, straightforward exploit mechanism, and direct availability impact makes it a practical risk. However, it does not affect confidentiality or integrity, and its scope is limited to adjacent networks. Organizations with strong network segmentation isolating WebSphere instances can deprioritize relative to externally reachable vulnerabilities, but should still patch as part of routine maintenance cycles.
Risk score, explained
CVSS 6.5 (MEDIUM) reflects a high-availability impact (denial of service) with no authentication or user interaction required, but constrained to an adjacent network (AV:A). The attack complexity is low, and scope is unchanged (the JVM crash is localized to the affected server). The score appropriately captures that this is a serious availability threat in accessible network segments but does not escalate to HIGH because it requires network adjacency and lacks confidentiality or integrity consequences.
Frequently asked questions
Do I need to be on the same physical network to exploit this?
The CVSS vector indicates adjacency (AV:A), which generally means the attacker must be on the same network segment or have Layer 2 access. In a switched Ethernet environment, this typically means the attacker must be on the same VLAN or subnet, or able to reach the service via direct routing. In cloud or virtualized environments, this could include other tenants in the same infrastructure.
Does this vulnerability expose data or allow code execution?
No. The vulnerability only causes a denial of service by crashing the JVM. There is no confidentiality impact (no data exposure) and no integrity impact (no data modification or code execution). The attacker can only disrupt availability.
What is Protocol Buffers and why does it matter here?
Protocol Buffers is a binary serialization format used by many distributed systems for efficient message passing. In this case, the WebSphere XDF decoder processes these serialized messages. The vulnerability exists because the decoder does not validate the depth or total size of nested messages before allocating memory or recursing, allowing an attacker to trigger resource exhaustion.
How quickly should we patch if we run WebSphere Extreme Scale?
If your instances are in an isolated or air-gapped environment with no untrusted network access, patch within your normal change-management cycle. If instances are in a shared network or cloud environment with potential for untrusted neighbor access, prioritize patching within 1–2 weeks alongside compensating network controls (firewall restrictions to trusted IPs).
This analysis is provided for informational purposes to help security teams understand and manage CVE-2026-9002. Patch version numbers, KEV status, and affected product lists are derived from official IBM security advisories and the NVD; verify against vendor documentation before deployment. SEC.co does not provide exploit code or weaponized proof-of-concept instructions. Organizations should conduct their own risk assessment based on network architecture, data criticality, and regulatory requirements. Consult IBM support for vendor-specific guidance on patching, testing, and compatibility. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-9320MEDIUMIBM WebSphere Denial-of-Service Vulnerability (CVSS 5.9)
- CVE-2026-9071HIGHIBM WebSphere Denial of Service Vulnerability – Memory Exhaustion Attack
- CVE-2019-25721MEDIUMDräger Infinity M300 Denial-of-Service Vulnerability – Network-Induced Device Reboots
- CVE-2019-25724MEDIUMDräger Infinity M300 Denial-of-Service Vulnerability Impact on Patient Monitoring
- CVE-2025-48648MEDIUMAndroid NotificationManagerService Resource Exhaustion DoS
- CVE-2026-0042MEDIUMAndroid UBSan Resource Exhaustion Denial of Service
- CVE-2026-0064MEDIUMAndroid Resource Exhaustion Denial of Service
- CVE-2026-0069MEDIUMAndroid Resource Exhaustion in APK Signature Verification