IBM Product Security Update Advisory (CVE-2026-4870)

IBM Product Security Update Advisory (CVE-2026-4870)
  • A security update has been released to address a vulnerability in an IBM product.
  • The affected product is the Qiskit SDK, and the vulnerable versions are listed as 0.43.0 through 2.5.0.
  • The vulnerability addressed is CVE-2026-4870.
  • This vulnerability is a denial-of-service (DoS) vulnerability in the Qiskit SDK.
  • According to the reference site, when a specific function encounters certain classical expressions, it may trigger excessively deep recursive calls, potentially causing the available stack space to overflow.
  • IBM announced that a Vulnerability Patch has been provided via the latest update.
  • Users of this product should update to the latest version with the Vulnerability Patch as instructed on the reference site.
  • The referenced patch versions are Qiskit SDK version 1.4.6 and Qiskit SDK version 2.4.2.