{"id":"CVE-2025-14575","title":"An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate …","summary":"An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate …","severity":"none","cwe":["CWE-427"],"published":"2026-05-19","updated":"2026-07-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14575","references":[{"url":"https://codereview.qt-project.org/c/qt/qtbase/+/642967","label":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"}],"tags":["nvd"],"epss":0.00092,"epssPercentile":0.00597,"ingestedAt":"2026-07-29T10:45:51.033Z","slug":"CVE-2025-14575","body":"## Overview\n\nAn Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}