CVE-2026-1718: IBM® Db2® is vulnerable to a denial of service with a specially crafted query when running an AUTONOMOUS procedure
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
Other sources
IBM Db2 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 11.5to a version that resolves this vulnerability.Fixed in V11.5.9 - Upgrade
Upgrade
IBM Db2 12.1to a version that resolves this vulnerability.Fixed in V12.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1718?
The severity of CVE-2026-1718 is high with a score of 7.5.
What kind of vulnerability is CVE-2026-1718?
CVE-2026-1718 is a denial of service vulnerability in IBM Db2 due to a specially crafted query.
Which versions of IBM Db2 are affected by CVE-2026-1718?
CVE-2026-1718 affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4.
How do I fix CVE-2026-1718?
To fix CVE-2026-1718, download the special build containing the interim fix from Fix Central.
What feature must be enabled for the exploit of CVE-2026-1718 to occur?
The exploit of CVE-2026-1718 occurs when autonomous transactions are enabled.