SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19795

MEDIUM · CVSS 6.2 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Qiskit SDK versions 2.1.0 to 2.5.1 are vulnerable to a denial of service attack due to improper deserialization of specially crafted objects, which can lead to application crashes. Local attackers can exploit this flaw by sending malicious QPY payloads, resulting in segmentation faults. Organizations utilizing these specific versions of the Qiskit SDK should prioritize patching to mitigate potential disruptions.

CVE
CVE-2026-19795
Severity
MEDIUM
CVSS
6.2
EPSS
0.11%

Original NVD Description

Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.