← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 20:17via CVEFeed

CVE-2026-19795 - Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.

Brief

CVE ID : CVE-2026-19795

Published : Sept. 3, 2026, 8:17 p. m.

  • 23 minutes ago

Description : IBM Qiskit SDK 2.

  • 0 through 2.
  • 1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.

Severity: 6.2

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed