CVE-2026-12733

Summary

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Affected Software

VendorProductVersion RangeStatus
IBMDataPower Gateway 10.6CD10.6.1 <= 10.6.6affected
IBMDataPower Gateway 10.6.010.6.0.0 <= 10.6.0.9affected
IBMDataPower Gateway 11.0.011.0.0.0 <= 11.0.0.1affected
IBMDataPower Gateway 10.5.010.5.0.0 <= 10.5.0.21affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

Workarounds

Disable HTTP/2.

References