- A security update has been released to address a vulnerability in an IBM product.
- The affected product is WebSphere Application Server – Liberty.
- The vulnerability is a denial-of-service (DoS) vulnerability (an attack that prevents normal use of a system or service) identified as CVE-2026-11897.
- A denial-of-service vulnerability related to HTTP/2 has been reported in IBM WebSphere Application Server – Liberty.
- Affected Versions range from 17.0.0.3 Through 26.0.0.7.
- The workaround is to update WebSphere Application Server – Liberty to version 26.0.0.8 Or later, or to apply the APAR PH71839 Interim Fix.
- IBM recommends updating to the latest version of the Vulnerability Patch as instructed on the reference site.