IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7285394 |
|
History
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature. | |
| Title | Multiple vulnerabilities in IBM MQ Agent images | |
| First Time appeared |
Ibm
Ibm mq Agent |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:ibm:mq_agent:cd:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm mq Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-09-04T15:20:24.432Z
Updated: 2026-09-04T15:20:24.432Z
Reserved: 2026-08-12T17:12:34.967Z
Link: CVE-2026-19645
No data.
Status : Awaiting Analysis
Published: 2026-09-04T16:17:24.923
Modified: 2026-09-08T14:17:08.940
Link: CVE-2026-19645
No data.