CVE-2026-19795

IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.

Credits

Issue discovered by Matthew Treinish (IBM) and Takashi Imamichi (IBM)

References