CVE-2026-11381 PUBLISHED

IBM MQ for HPE NonStop is vulnerable to a denial of service issue

Assigner: ibm
Reserved: 05.06.2026 Published: 18.09.2026 Updated: 19.09.2026

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product MQ for HPE NonStop
Versions
  • affected from 8.1.0 to 8.1.0.40 (incl.)

Solutions

IBM MQ V8.1 for HPE NonStop 8.1.0.40IT49925Upgrade to CSU 8.1.0.41 IBM strongly recommends addressing this vulnerability now by installing CSU 8.1.0.41.

References

Problem Types

  • CWE-122 Heap-based Buffer Overflow CWE