CVE-2026-19795 - Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.
Brief
CVE ID : CVE-2026-19795
Published : Sept. 3, 2026, 8:17 p. m.
- 23 minutes ago
Description : IBM Qiskit SDK 2.
- 0 through 2.
- 1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.
Severity: 6.2
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
