Severity
6.5MEDIUMNVD
CNA6.0
EPSS
0.2%
top 63.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateFeb 11

Description

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5ibm/mq_operator2.0.0 LTS2.0.29 LTS+2
NVDibm/mq_operator2.0.02.0.29+12

🔴Vulnerability Details

21
GHSA
PyMdown Extensions has a ReDOS bug in its Figure Capture extension2025-12-16
GHSA
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability2025-10-16
GHSA
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer2025-09-12
GHSA
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity2025-09-09
GHSA
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module2025-08-20

📋Vendor Advisories

31
Red Hat
ajv: ReDoS via $data reference2026-02-11
Microsoft
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Poin2026-02-10
Red Hat
PyMdown: pymdown-extensions: PyMdown Extensions: Regular Expression Denial of Service in figure caption extension2025-12-16
Red Hat
tornado: Tornado Quadratic DoS via Crafted Multipart Parameters2025-12-12
Red Hat
sinatra: Sinatra has ReDoS vulnerability in ETag header value generation2025-10-10
CVE-2025-1333 — IBM MQ Operator vulnerability | cvebase