---
id: CVE-2026-19645
title: >-
  IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a
  valid session cookie can submit arbitrarily large or computationallyexpensive
  requests that cause the LLM agent workers to be held for extended periods —
  rangin…
summary: >-
  IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a
  valid session cookie can submit arbitrarily large or computationallyexpensive
  requests that cause the LLM agent workers to be held for extended periods —
  rangin…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: IBM
product: MQ Agent
affected:
  - 'mq_agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1'
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:26.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19645'
references:
  - url: 'https://www.ibm.com/support/pages/node/7285394'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:38:37.341225Z'
epss: 0.00289
epssPercentile: 0.19097
ingestedAt: '2026-09-08T15:33:26.962Z'
---

## Overview

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
