CVE-2026-19795

Summary

IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.

Affected Software

VendorProductVersion RangeStatus
IBMQiskit SDK2.1.0 <= 2.5.1affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of Untrusted Data

Workarounds

Workarounds/Mitigation guidance:

None

References