CVE-2026-7771: IBM DB2

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of service.

Affected products

  • IBM DB2: from 11.5.0, up to and including 11.5.9; from 12.1.0, before 12.1.5 (fixed in 12.1.5)

Published 2026-07-17. Last modified 2026-07-24.