{"data":{"id":"8fac830c-7e3b-4107-88fa-5a7892a7df08","title":"CVE-2026-19645: IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily","summary":"In IBM MQ Agent CD versions 1.0.0, 1.0.1, 2.0.0, and 2.0.1, a logged-in user can send extremely large or computationally expensive requests that tie up the LLM agent workers (the programs handling AI tasks) for very long periods, sometimes over ten minutes each. When many such requests are sent at once, all the available workers become blocked, making the AI Agent feature slow or completely unavailable for other users.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19645","publishedAt":"2026-09-04T16:17:24.923Z","cveId":"CVE-2026-19645","cweIds":["CWE-400"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["IBM MQ Agent CD"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-04T16:17:24.923Z","capecIds":["CAPEC-125","CAPEC-130"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}