VYPR
Medium severity6.5NVD Advisory· Published Sep 4, 2026

CVE-2026-19645

CVE-2026-19645

Description

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • IBM/MQ Agentllm-create
    Range: v1.0.0, v1.0.1, v2.0.0, v2.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.