No analysis available yet.
Vendor Solution
Issues mentioned by this security bulletin are addressed in IBM MQ Agent v2.0.2 image. IBM strongly recommends applying the latest agent images. IBM MQ Agent v2.0.2 release details: Image Fix Version Registry Image Location ibm-mq-agent-runtime v2.0.2 cp.icr.io cp.icr.io/cp/ibm-mq-agent-runtime:v2.0.2@sha256:564a3ea85fb601b6bcad4edfd1fe681430d3302338566eb9a554b76e88dc5381 ibm-mq-agent-mcp v2.0.2 cp.icr.io cp.icr.io/cp/ibm-mq-agent-mcp:v2.0.2@sha256:400e94ea5312a1307a03e4098506d2e30f7638a0c1410992ce50c59f5cf7a25e ibm-mq-agent-embedding-service v2.0.2 cp.icr.io cp.icr.io/cp/ibm-mq-agent-embedding-service:v2.0.2@sha256:1c324e024462984462a0c7286b7249f76ee1f3bd08000cddf6e431766eea5d7a
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285394 |
|
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature. | |
| Title | Multiple vulnerabilities in IBM MQ Agent images | |
| First Time appeared |
Ibm
Ibm mq Agent |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:ibm:mq_agent:cd:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm mq Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-04T15:20:24.432Z
Reserved: 2026-08-12T17:12:34.967Z
Link: CVE-2026-19645
No data.
Status : Received
Published: 2026-09-04T16:17:24.923
Modified: 2026-09-04T16:17:24.923
Link: CVE-2026-19645
No data.
OpenCVE Enrichment
No data.
-
CWE-400
Uncontrolled Resource Consumption