qiskit-terra
Software for developing quantum computing programs
Activity
- Latest release
- 1y ago
- Total releases
- 73
- Cadence
- ~20 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Dec 19, 2018
| Version | Released | |
|---|---|---|
0.46.3
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.46.2
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.46.1
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.46.0
minor
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.45.3
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.45.2
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.45.1
patch
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.45.0
minor
2 CVEs
CVE-2025-1403
PYSEC-2026-1859
GHSA-fpmr-m242-xm7x
PYSEC-2026-3045
Jul 07, 2026
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
8.6
/ 10
High
Network
Low
None
None
Changed
None
None
High
ImpactA maliciously crafted QPY file containing a malformed PatchesThis issue is addressed in 1.3.0 when using QPY format version 13. QPY format versions 10, 11, and 12 are all still inherently vulnerable if they are using symengine symbolic encoding and The symengine 0.14.0 release has addressed the segfault issue, but it is backward incompatible and will not work with any Qiskit release; it also prevents loading a payload generated with any other version of symengine. Using QPY 13 is strongly recommended for this reason. It is also strongly suggested to patch the locally installed version of symengine in the deserializing environment to prevent the specific segfault. The commit [1] can be applied on top of symengine 0.13.0 and used to build a patched python library that will not segfault in the presence of a malformed payload and instead raise a WorkaroundsAs QPY is backwards compatible
Note, this function does not tell you whether the payload is malicious and will cause the segfault, just that conditions for it to be potentially malicious exist. It's not possible to know ahead of time whether References[1] https://github.com/symengine/symengine/commit/eb3e292bf13b2dfdf0fa1c132944af8df2bc7d51 Affected versions
0.45.0
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.3
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.45.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.2.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.25.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.24.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.24.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.24.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.24.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.23.3
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.23.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.23.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.23.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.23.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.4
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.3
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.22.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.21.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.21.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.21.0rc1
pre
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.20.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.20.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.20.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.19.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.19.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.19.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.18.3
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.18.2
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.18.1
patch
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.18.0
minor
1 CVE
CVE-2025-2000
PYSEC-2026-511
GHSA-6m2c-76ff-6vrf
PYSEC-2026-510
Jun 29, 2026
Qiskit allows arbitrary code execution decoding QPY format versions < 13
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactA maliciously crafted QPY file can potentially execute arbitrary-code embedded in the payload without privilege escalation when deserializing QPY formats < 13. A python process calling Qiskit's PatchesFixed in Qiskit 1.4.2 and in Qiskit 2.0.0rc2 Affected versions
0.18.0
0.18.1
0.18.2
0.18.3
0.19.0
0.19.1
0.19.2
0.20.0
0.20.1
0.20.2
0.21.0
0.21.0rc1
+ 32 more Show less
0.21.1
0.21.2
0.22.0
0.22.0rc1
0.22.1
0.22.2
0.22.3
0.22.4
0.23.0
0.23.0rc1
0.23.1
0.23.2
0.23.3
0.24.0
0.24.0rc1
0.24.1
0.24.2
0.25.0
0.25.0rc1
0.25.1
0.25.2
0.25.2.1
0.25.3
0.45.0
0.45.0rc1
0.45.1
0.45.2
0.45.3
0.46.0
0.46.1
0.46.2
0.46.3
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.17.4
patch
| ||
0.17.3
patch
| ||
0.17.2
patch
| ||
0.17.1
patch
| ||
0.17.0
minor
| ||
0.16.4
patch
|