CVE-2026-1577: IBM® Db2® is vulnerable to a denial of service with a specially crafted query involving multiple subqueries
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
Other sources
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1577?
CVE-2026-1577 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2026-1577?
To fix CVE-2026-1577, upgrade IBM Db2 to the latest version that is not affected, as detailed in IBM's security documentation.
Who is affected by CVE-2026-1577?
CVE-2026-1577 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux, UNIX, and Windows.
What kind of attack does CVE-2026-1577 expose?
CVE-2026-1577 exposes IBM Db2 to denial of service attacks through specially crafted queries involving multiple subqueries.
Is CVE-2026-1577 exploitable remotely?
CVE-2026-1577 is not exploitable remotely as it requires an authenticated user to trigger the denial of service.