CVE-2026-6051
Analyzed Analyzed - Analysis Complete
Denial of Service in IBM Db2 Database

Publication date: 2026-05-27

Last updated on: 2026-05-28

Assigner: IBM Corporation

Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-28
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm db2 From 11.5.0 (inc) to 11.5.9 (inc)
ibm db2 From 12.1.0 (inc) to 12.1.4 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-6051 is a vulnerability in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 that allows a denial of service (DoS) attack. This occurs when a specially crafted query is executed with a small statement heap, leading to uncontrolled resource consumption.

Impact Analysis

The vulnerability can cause a denial of service condition in IBM Db2, making the database unavailable or unresponsive. This can disrupt normal operations and affect applications relying on the database, potentially leading to downtime and loss of availability.

Detection Guidance

IBM advises assessing the impact of the vulnerability in your environment, but does not provide specific detection commands or network/system detection methods.

Detailed exploitation steps or detection commands are not disclosed to prevent potential misuse.

Mitigation Strategies

To mitigate the vulnerability, IBM recommends applying interim fixes available for Db2 versions 11.5.9 and 12.1.4 through Fix Central.

Alternatively, you can increase the statement heap size by setting a larger STMTHEAP value.

Another workaround is to reduce the optimization level to 0 by appending an optimizer guideline to the query.

It is important to apply these fixes or workarounds promptly after assessing their impact in your environment.

Compliance Impact

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6051. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart