CVE-2026-12150
Received Received - Intake

Denial of Service in IBM MQ via TLS Certificate Processing

Vulnerability report for CVE-2026-12150, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
ibm mq From 9.1.0.0 (inc) to 9.1.0.37 (inc)
ibm mq From 9.2.0.0 (inc) to 9.2.0.43 (inc)
ibm mq From 9.3.0.0 (inc) to 9.3.0.41 (inc)
ibm mq From 9.3.0.0 (inc) to 9.3.5.1 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.0.25 (inc)
ibm mq From 9.4.0.0 (inc) to 9.4.5.1 (inc)
ibm mq 10.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service (DoS) flaw in IBM MQ caused by improper validation of deeply nested TLS certificate data. A remote attacker with a trusted TLS client certificate could exploit unbounded recursion in the certificate parser to cause a DoS and potentially corrupt memory contents.

Detection Guidance

To detect this vulnerability, monitor for unusual memory usage or crashes in IBM MQ server processes. Check for excessive CPU usage during TLS handshake attempts. Inspect logs for failed TLS connections or certificate parsing errors. Use network monitoring tools to identify repeated TLS handshake attempts from the same client.

Impact Analysis

It could allow attackers to disrupt IBM MQ server operations, leading to service unavailability. Memory corruption may also occur, potentially causing crashes or unpredictable behavior in the affected system.

Compliance Impact

This vulnerability could impact compliance by disrupting data availability and integrity, which are critical for GDPR and HIPAA. Downtime or data corruption may lead to violations of these regulations.

Mitigation Strategies

Apply the latest IBM MQ updates immediately: for LTS versions upgrade to 9.1.0.38, 9.2.0.44, 9.3.0.42, or 9.4.0.26. For CD versions and 10.0.0.0, upgrade to 10.0.0.5. Disable TLS client certificate authentication temporarily if possible until patches are applied. Monitor system performance and memory usage closely after applying fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12150. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart