{"id":"CVE-2026-19395","title":"In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value","summary":"In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty valu…","severity":"medium","cvss":6.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U","cwe":["CWE-230","CWE-617"],"vendor":"qt","product":"Qt for MCUs","affected":["for_mcus >= 2.12.0 < 2.12.3"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T13:16:53.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19395","references":[{"url":"https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-19395:","label":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-05T12:00:28.733595Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T10:17:16.615Z","slug":"CVE-2026-19395","body":"## Overview\n\nIn Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":36.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}