CVE-2025-1403: IBM Qiskit
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
Affected products
- IBM Qiskit: from 0.45.0, up to and including 1.2.4
Published 2025-02-21. Last modified 2026-06-17.