[Development] [Announce] Security advisory: CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt
List for announcements regarding Qt releases and development via Announce
announce at qt-project.org
Wed Sep 23 13:22:56 CEST 2026
A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253.
[cid:ec719d4e-aed1-44be-a0fb-98353e0b04a2]
Affected versions: From Qt 5.0 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1
Impact: When a deeply nested XML document is passed to QXmlStreamReader::readElementText(), the recursive parsing can exhaust the call stack and crash the application, even for moderately sized inputs. Such documents may originate from untrusted sources, for example via XMLHttpRequest in QML or data fetched with QNetworkAccessManager.
CVSS 4.0 Score: 2.3 / Low
Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/RE:L/U:Green
Mitigation: Count and restrict the nesting level of XML documents before parsing them with QXmlStreamReader.
Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2, or later.
Patches:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/754345
Qt 6.11: https://codereview.qt-project.org/c/qt/qtbase/+/756741 or https://download.qt.io/official_releases/qt/6.11/CVE-2026-78253-qtbase-6.11.diff
Qt 6.10: https://codereview.qt-project.org/c/qt/qtbase/+/763174 or https://download.qt.io/official_releases/qt/6.10/CVE-2026-78253-qtbase-6.10.diff
Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/756872 or https://download.qt.io/official_releases/qt/6.8/CVE-2026-78253-qtbase-6.8.diff
Tero Pelkonen
Qt Group
Confidential
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.qt-project.org/pipermail/development/attachments/20260923/d6b69657/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image.png
Type: image/gif
Size: 42 bytes
Desc: image.png
URL: <http://lists.qt-project.org/pipermail/development/attachments/20260923/d6b69657/attachment.gif>
-------------- next part --------------
_______________________________________________
Announce mailing list
Announce at qt-project.org
https://lists.qt-project.org/listinfo/announce
More information about the Development
mailing list