CVE-2026-12150: IBM MQ queue manager is vulnerable to denial of service
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.
Other sources
IBM MQ could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and potentially affect memory contents due to improper validation of deeply nested certificate data during TLS certificate processing.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM MQ 9.1 LTSto a version that resolves this vulnerability.Fixed in 9.1.0.38 - Upgrade
Upgrade
IBM MQ 9.2 LTSto a version that resolves this vulnerability.Fixed in 9.2.0.44 - Upgrade
Upgrade
IBM MQ 9.3 LTSto a version that resolves this vulnerability.Fixed in 9.3.0.42 - Upgrade
Upgrade
IBM MQ 9.4 LTSto a version that resolves this vulnerability.Fixed in 9.4.0.26 - Upgrade
Upgrade
IBM MQ 10.0to a version that resolves this vulnerability.Fixed in 10.0.0.5
Event History
Frequently Asked Questions
What must an attacker have to exploit this issue?
The attacker must be able to connect remotely and present a TLS client certificate that the affected IBM MQ queue manager trusts. No additional privileges or user interaction are identified in the provided data.
Which deployments are exposed?
Affected deployments are IBM MQ queue managers in the listed 9.1, 9.2, 9.3, 9.4, and 10.0.0.0 releases that process trusted TLS client certificates. The issue occurs during TLS certificate processing of deeply nested certificate data.
What is the likely impact of a successful attack?
A successful attack can cause a denial of service. It may also potentially affect memory contents, with the supplied severity vector indicating low confidentiality and integrity impact alongside high availability impact.