
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-36001 is an uncontrolled recursion vulnerability in IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) that allows an authenticated user to cause a denial of service via a specially crafted SQL statement containing XML. Affected versions include 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 across all supported platforms. The vulnerability was published on January 30, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 6.5 (Medium) (IBM Support, Red Hat CVE).
The vulnerability is classified as CWE-674 (Uncontrolled Recursion) and resides in IBM Db2's XML processing subsystem. An authenticated attacker can submit a specially crafted SQL statement that includes XML content designed to trigger deeply nested or infinite recursion within the database engine. The attack vector is network-based, requires low privileges (valid database credentials), and no user interaction, making it straightforward to exploit once access is obtained. No complex preconditions beyond authentication are required (IBM Support, Red Hat CVE).
Successful exploitation results in a high availability impact — the affected Db2 instance can become unresponsive, crash, or consume excessive system resources, disrupting database service for all dependent applications and users. There is no confidentiality or integrity impact, as the vulnerability is limited to a denial-of-service condition. The scope is unchanged, meaning the impact is confined to the affected Db2 instance itself without lateral spread to other systems (IBM Support).
IBM has released security patches for all affected versions; administrators should apply the updates referenced in IBM Support page node/7257616 for their specific version (11.5.0–11.5.9 or 12.1.0–12.1.3). As interim mitigations, restrict database access to only authenticated users who require it and enforce the principle of least privilege for database accounts. Additionally, monitor for and consider filtering SQL statements containing deeply nested or recursive XML structures, and review database audit logs for suspicious XML-based query patterns (IBM Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."