Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Remediation/Fixes guidance: The issue is addressed in Qiskit versions v2.5.2. This version is patched to prevent the stack overflow by no longer evaluating the expression tree for ParameterExpression objects recursively. Product(s)Version(s) number and/or range Remediation/Fix/Instructions<Qiskit SDK - qiskit.qpy.load() function>v2.5.2 Upgrade to the patched versions: qiskit v2.5.2.
Vendor Workaround
Workarounds/Mitigation guidance: None
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285932 |
|
Fri, 04 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. | Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. |
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input. | |
| Title | Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space. | |
| First Time appeared |
Ibm
Ibm qiskit Sdk |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:ibm:qiskit_sdk:2.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:qiskit_sdk:2.5.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm qiskit Sdk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-04T20:05:30.490Z
Reserved: 2026-08-13T19:40:18.000Z
Link: CVE-2026-19795
Updated: 2026-09-04T13:26:20.465Z
Status : Received
Published: 2026-09-03T20:17:19.790
Modified: 2026-09-04T21:17:24.733
Link: CVE-2026-19795
No data.
OpenCVE Enrichment
Updated: 2026-09-03T21:45:09Z