Junglewise Threat Intelligence

CVE-2026-11381: IBM MQ heap-based buffer overflow in distribution lists

CVE-2026-11381 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: IBM MQ for HPE NonStop. Vendors: IBM.

Executive brief

IBM MQ is an enterprise message-queuing system that routes business messages across distributed networks. An authenticated attacker can exploit improper validation of message distribution list structures to cause service outages or execute arbitrary code on the affected system. This vulnerability requires valid credentials to exploit.

Technical details

A heap-based buffer overflow (CWE-122) in IBM MQ's handling of distribution list structures allows authenticated network attackers to trigger denial of service or arbitrary code execution without user interaction. The vulnerability stems from inadequate input validation when processing specially crafted distribution list messages. A fix is available via CSU 8.1.0.41 for IBM MQ V8.1 on HPE NonStop.

Affected products

  • IBM MQ for HPE NonStop 8.1.0.0 through 8.1.0.40

Timeline

  • 2026-09-17: disclosed

References

Related threats