CVE-2026-6052
published 2026-05-27CVE-2026-6052: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.24%
15.3th percentile
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | 11.5.0 – 11.5.9 | — |
| ibm | db2 | 12.1.0 – 12.1.4 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gpjv-6r8h-vp58: IBM Db2 11
ghsa_unreviewed·2026-05-27
CVE-2026-6052 [MEDIUM] CWE-400 GHSA-gpjv-6r8h-vp58: IBM Db2 11
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) — CVE-2025-6052
vendor_oracle·2026-01-15·CVSS 3.7
CVE-2025-6052 [LOW] Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) — CVE-2025-6052
Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) vulnerability
CVE: CVE-2025-6052
CVSS: 3.7
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published