PatchSiren

qt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM qt CVE published 2026-09-16

CVE-2026-76151

CVE-2026-76151 is a medium-severity vulnerability in Qt Group Qt 6.0.0 through 6.8.8 and 6.9.0 through 6.11.1. It allows remote attackers to cause a denial of service via an excessively large Cache-Control header value. Only the client side is affected, and 32-bit builds are not vulnerable. The vulnerability is an out-of-bounds read in the HTTP Cache-Control response header parsing in the QtNetwork module [truncated]

HIGH qt CVE published 2026-09-16

CVE-2026-19248

CVE-2026-19248 is a denial-of-service vulnerability in QDomDocument XML parsing. Defenders should assess exposure, prioritize verification, and monitor for potential crashes. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. However, the CVE record and NVD entry provide limited information about the vulnerability, and further verification is required to determine affected systems [truncated]

MEDIUM qt CVE published 2026-09-11

CVE-2026-13326

A physically proximate attacker may cause a denial of service or limited memory disclosure via a crafted NFC tag due to an out-of-bounds read in Qt NFC's language code length parsing. This vulnerability impacts systems processing NFC tags in close proximity, particularly those using Qt NFC for tag handling. Defenders should assess exposure and prioritize patching for systems where NFC tags are processed i [truncated]

HIGH qt CVE published 2026-09-08

CVE-2026-11573

CVE-2026-11573 is a high-severity denial-of-service vulnerability in the Qt XML module (QtXml, qtbase) due to uncontrolled recursion in the QDomDocument/QDomNode serialization path. A document with deeply nested elements can exhaust the call stack and terminate the process when serialized. This vulnerability is reachable via several functions, including QDomDocument::toByteArray(), QDomDocument::toString( [truncated]

MEDIUM Qt CVE published 2026-07-21

CVE-2026-9499

An out-of-bounds read vulnerability exists in QTextCodec::codecForName() in Qt. The function is called with a QByteArray that is not NUL-terminated, the codec-name matching routine reads past the end of the supplied buffer. This can lead to an incorrect text codec being selected or, in the worst case, a denial of service if the over-read reaches unmapped memory. The affected code resides in the Qt5Compat [truncated]

MEDIUM Qt CVE published 2026-07-16

CVE-2026-12379

CVE-2026-12379 is an Open Redirect vulnerability in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect to the application's own origin, allowing a user who follows a crafted login link to be sent to an untrusted external site after authenticating against the genuine Dashboard. This vulnerability can be abused for [truncated]

HIGH Qt CVE published 2026-07-09

CVE-2026-12593

CVE-2026-12593 involves an undocumented Dashboard API endpoint that could allow an attacker to create an API token for another user, potentially leading to high privileges. This vulnerability affects systems using the Dashboard API and requires immediate attention from administrators and users. The attack would require a preexisting internal user with more privileges than the attacker, knowledge of the us [truncated]

HIGH Qt CVE published 2026-04-30

CVE-2025-14576

CVE-2025-14576 is a high-severity vulnerability in the Qt SVG module. Insufficient validation of node IDs allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. This could lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access. The vulnerability has a CVSS sco [truncated]

MEDIUM Qt CVE published 2017-03-07

CVE-2016-10040

CVE-2016-10040 is a stack-based buffer overflow in Qt's QXmlSimpleReader affecting Qt 4.8.5. According to the NVD record, an XML file with multiple nested open tags can trigger an application crash, resulting in denial of service. The NVD CVSS vector rates the issue as medium severity and shows availability impact only.