VYPR
High severity8.6NVD Advisory· Published Feb 21, 2025· Updated Jun 17, 2026

CVE-2025-1403

CVE-2025-1403

Description

Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
qiskitPyPI
>= 0.45.0, < 1.3.01.3.0
qiskit-terraPyPI
>= 0.45.0, <= 0.46.3

Affected products

4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.