CVE-2026-16182: IBM Datapower Gateway 10.5.0

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM DataPower Gateway 10.5.0.0 through 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow an attacker to cause a denial of service due to a NULL pointer dereference in GraphQL variable processing.

Affected products

  • IBM Datapower Gateway 10.5.0: from 10.5.0.0, up to and including 10.5.0.22
  • IBM Datapower Gateway 10.6.0: from 10.6.0.0, up to and including 10.6.0.10
  • IBM Datapower Gateway 10.6cd: from 10.6.1, up to and including 10.6.6
  • IBM Datapower Gateway 11.0.0: from 11.0.0.0, up to and including 11.0.0.2

Published 2026-10-08. Last modified 2026-10-08.