{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/websphere-application-server---liberty-17.0.0.3-through-26.0.0.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-16192"},{"cvss":7.1,"id":"CVE-2026-14976"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WebSphere Application Server - Liberty","WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","websphere"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed CVE-2026-16192, a denial of service vulnerability impacting IBM WebSphere Application Server - Liberty, specifically versions ranging from 17.0.0.3 up to and including 26.0.0.8. The vulnerability, classified as uncontrolled recursion (CWE-674), manifests when the \u003ccode\u003erestConnector-2.0\u003c/code\u003e feature is enabled within the server configuration. While the specific mechanism of triggering the recursion is not detailed, an attacker with network access could send specially crafted requests to the server, exploiting this flaw to consume excessive resources and ultimately render the application server unresponsive. This vulnerability carries a CVSS v3.1 base score of 7.1 (High), indicating a significant impact on system availability if exploited. Defenders should prioritize patching or implementing mitigating controls to prevent service disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16192 leads to a denial of service (DoS) condition on the affected IBM WebSphere Application Server - Liberty instance. This means the server could become unresponsive or crash, severely disrupting the services and applications hosted on it. The unavailability of critical business applications can result in significant operational losses, reputational damage, and financial repercussions for organizations. The vulnerability specifically targets the availability of the system and does not mention data confidentiality or integrity being compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest security updates and patches provided by IBM for WebSphere Application Server - Liberty to address CVE-2026-16192. Refer to the IBM security bulletin referenced for specific patch details.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, disable the \u003ccode\u003erestConnector-2.0\u003c/code\u003e feature in your IBM WebSphere Application Server - Liberty configurations if it is not essential for operations. This mitigates the risk of exploitation for CVE-2026-16192.\u003c/li\u003e\n\u003cli\u003eMonitor IBM support pages for additional guidance or updated advisories related to CVE-2026-16192.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T21:26:10Z","date_published":"2026-07-28T20:21:57Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16192-liberty-dos/","summary":"A denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.","title":"IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16192-liberty-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - WebSphere Application Server - Liberty 17.0.0.3 Through 26.0.0.8","version":"https://jsonfeed.org/version/1.1"}