Impact
IBM MQ Agent is vulnerable to an authenticated denial of service attack that arises when a user with a valid session cookie submits exceptionally large or computationally expensive requests to the LLM agent workers. These requests consume worker resources for extended periods, from tens of seconds to over ten minutes, causing the worker pool to become saturated. The resulting degradation or complete unavailability of the AI Agent feature can affect all users logged into the IBM MQ Console, potentially disrupting business workflows that rely on the AI agent.
Affected Systems
The vulnerability affects IBM MQ Agent images in versions v1.0.0, v1.0.1, v2.0.0, and v2.0.1. The affected Docker images include ibm-mq-agent-runtime, ibm-mq-agent-mcp, and ibm-mq-agent-embedding-service, all of which are listed under the IBM:MQ Agent CNA vendor.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderate severity. The EPSS score is not available, leaving the exact exploitation probability uncertain, but the fact that the flaw requires only an authenticated session cookie suggests it can be easily leveraged by compromised or privileged accounts. The vulnerability is not currently listed in CISA's KEV catalog, but its denial‑of‑service impact warrants immediate attention. Attackers can exploit the flaw by crafting large or computationally heavy requests within their session, potentially exhausting the worker pool and degrading service for all users.
OpenCVE Enrichment