Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Remediation/Fixes guidance: The issue is addressed in Qiskit versions v2.5.2. This version is patched to prevent the stack overflow by no longer evaluating the expression tree for ParameterExpression objects recursively. Product(s)Version(s) number and/or range Remediation/Fix/Instructions<Qiskit SDK - qiskit.qpy.load() function>v2.5.2Upgrade to the patched versions: qiskit v2.5.2.
Vendor Workaround
Workarounds/Mitigation guidance: None
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285932 |
|
Thu, 03 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. | |
| Title | Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space. | |
| First Time appeared |
Ibm
Ibm qiskit Sdk |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:ibm:qiskit_sdk:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qiskit_sdk:2.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm qiskit Sdk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-03T19:56:03.172Z
Reserved: 2026-08-13T19:40:18.000Z
Link: CVE-2026-19795
No data.
Status : Received
Published: 2026-09-03T20:17:19.790
Modified: 2026-09-03T20:17:19.790
Link: CVE-2026-19795
No data.
OpenCVE Enrichment
Updated: 2026-09-03T21:30:05Z