SB2026092114 - Multiple vulnerabilities in IBM Db2 Developer Extension



SB2026092114 - Multiple vulnerabilities in IBM Db2 Developer Extension

Published: September 21, 2026

Security Bulletin ID SB2026092114
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-41850)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Spring Expression Language (SpEL) expression evaluator when processing user-supplied SpEL expressions. A remote attacker can send a specially crafted expression to cause a denial of service.

The issue affects applications that accept and evaluate untrusted or user-controlled SpEL expressions.


2) Resource exhaustion (CVE-ID: CVE-2026-41851)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the SpEL expression cache when evaluating user-supplied SpEL expressions. A remote attacker can submit crafted expressions to cause a denial of service.

Exploitation requires that the application accept and evaluate untrusted SpEL expressions and cache parsed SpEL expressions. A high volume of processing is typically required, often involving millions of evaluations, including with a single expression using dynamic inputs.


3) Protection mechanism failure (CVE-ID: CVE-2026-41852)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to invoke unintended application logic.

The vulnerability exists due to improper restriction of operations within the Spring Expression Language evaluation logic in SpEL expression evaluation when evaluating untrusted or user-controlled expressions. A remote attacker can supply a crafted expression to invoke unintended application logic.

Arbitrary zero-argument method invocation is possible even within restricted or read-only contexts.


Remediation

Install update from vendor's website.