{"id":"CVE-2026-95509","title":"Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.","summary":"Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.","severity":"high","cvss":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-125","CWE-131"],"vendor":"qt","product":"Qt for MCUs","affected":["for_mcus >= 2.6.0 < 2.11.3","for_mcus >= 2.12.0 < 2.12.3"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T11:16:43.947","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95509","references":[{"url":"https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-95509:","label":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-29T11:32:41.244Z","slug":"CVE-2026-95509","body":"## Overview\n\nStrings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}