CVE-2026-19645

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 16:17

Updated : 2026-09-10 21:17


NVD link : CVE-2026-19645

Mitre link : CVE-2026-19645

CVE.ORG link : CVE-2026-19645


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption