CVE-2026-19795: IBM Qiskit SDK

Medium severity, CVSS 6.2. EPSS: 0.1% chance of exploitation in the next 30 days.

Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.

Affected products

  • IBM Qiskit SDK: from 2.1.0, up to and including 2.5.1

Published 2026-09-03. Last modified 2026-09-08.