CVE-2026-17440
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-674
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- IBM App Connect Enterprise
- IBM App Connect Enterprise
- IBM Integration Bus for z/OS
Weakness type
Related vulnerabilities
- CVE-2026-22591 — Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS)
- CVE-2026-19201 — Denial of Service via Unbounded Recursion in go-attestation Windows SIPA Parser
- CVE-2026-69378 — Microsoft Exchange Server Denial of Service Vulnerability
- CVE-2026-73321 — XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser
- CVE-2026-11573 — QDomDocument::toByteArray() crashes when parsing svg file
- CVE-2026-77465 — toml-node: Uncontrolled Recursion
- CVE-2026-84851 — Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
- CVE-2026-14255 — IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products