IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specially crafted SQL statement including XML that performs uncontrolled recursion.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-36001.json"
[
{
"events": [
{
"introduced": "11.5.0"
},
{
"last_affected": "11.5.9"
}
]
},
{
"events": [
{
"introduced": "11.5.0"
},
{
"last_affected": "11.5.9"
}
]
},
{
"events": [
{
"introduced": "11.5.0"
},
{
"last_affected": "11.5.9"
}
]
},
{
"events": [
{
"introduced": "12.1.0"
},
{
"last_affected": "12.1.3"
}
]
},
{
"events": [
{
"introduced": "12.1.0"
},
{
"last_affected": "12.1.3"
}
]
},
{
"events": [
{
"introduced": "12.1.0"
},
{
"last_affected": "12.1.3"
}
]
}
]