- A security update has been released to address a vulnerability in an IBM product.
- The affected product is the Qiskit SDK, and the vulnerable versions are listed as 0.43.0 through 2.5.0.
- The vulnerability addressed is CVE-2026-4870.
- This vulnerability is a denial-of-service (DoS) vulnerability in the Qiskit SDK.
- According to the reference site, when a specific function encounters certain classical expressions, it may trigger excessively deep recursive calls, potentially causing the available stack space to overflow.
- IBM announced that a Vulnerability Patch has been provided via the latest update.
- Users of this product should update to the latest version with the Vulnerability Patch as instructed on the reference site.
- The referenced patch versions are Qiskit SDK version 1.4.6 and Qiskit SDK version 2.4.2.