---
id: CVE-2025-5455
title: >-
  An issue was found in the private API function qDecodeDataUrl() in QtCore,
  which is used in QTextDocument and QNetworkReply, and, potentially, in user
  code.




  If the function was called with malformed data, for example, an URL that

  cont…
summary: >-
  An issue was found in the private API function qDecodeDataUrl() in QtCore,
  which is used in QTextDocument and QNetworkReply, and, potentially, in user
  code.




  If the function was called with malformed data, for example, an URL that

  cont…
severity: none
cwe:
  - CWE-20
published: '2025-06-02'
updated: '2026-07-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5455'
references:
  - url: 'https://codereview.qt-project.org/c/qt/qtbase/+/642006'
    label: a59d8014-47c4-4630-ab43-e1b13cbe58e3
tags:
  - nvd
epss: 0.0038
epssPercentile: 0.31774
ingestedAt: '2026-07-29T09:45:30.532Z'
---

## Overview

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.



If the function was called with malformed data, for example, an URL that
contained a "charset" parameter that lacked a value (such as
"data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).



This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
