Junglewise Threat Intelligence

CVE-2026-17177: IBM Db2 Mirror for i denial of service via uncontrolled recursion

CVE-2026-17177 · Severity: high · CVSS 7.5 · Published 2026-08-14

Technologies: IBM Db2 Mirror For I. Vendors: IBM.

Executive brief

IBM Db2 Mirror for i is a database mirroring solution used to ensure high availability and disaster recovery for IBM database systems. A remote attacker can exploit an uncontrolled recursion vulnerability to crash the service, causing a denial of service and disrupting business-critical database operations without requiring authentication.

Technical details

This vulnerability is caused by uncontrolled recursion in IBM Db2 Mirror for i, which allows a remote, unauthenticated attacker to trigger excessive recursive function calls. The vulnerable component processes incoming requests without properly limiting recursion depth. An attacker can craft a specially formed network request to exploit this flaw, causing the service process to exhaust stack memory and crash, resulting in denial of service. The vulnerability affects versions 7.4, 7.5, and 7.6, and patches are available from IBM.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-08-14: disclosed

References

Related threats