Vulnerabilities & PatchesEmerging1 src
CVE-2026-19795 - Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.
CVE ID : CVE-2026-19795
Published : Sept. 3, 2026, 8:17 p. m.
• 23 minutes ago
Description : IBM Qiskit SDK 2. 1. 0 through 2. 5. 1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.
Severity: 6.2
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...