VulnSea

qt has 6 CVEs on record between 2025 and 2026. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.0 (high). None have a confirmed exploitation report. Most affected products: qt (5), qtdeclarative (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
4 prev 1

Products

  • qt 5
  • qtdeclarative 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

qt vulnerabilities

CVEs affecting qt, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-76151Medium· 4.6
6d ago

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (applicati…

Sunlitqt · qtEPSS 0.64%via NVD
CVE-2026-19248High· 7.1
6d ago

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

Twilightqt · qtEPSS 0.41%via NVD
CVE-2026-13326Medium· 6.9
1w ago

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

Sunlitqt · qtEPSS 0.15%via NVD
CVE-2026-11573High· 7.1
2w ago

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase)

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of elemen…

Twilightqt · qtEPSS 0.39%via NVD
CVE-2025-14576High· 7.8
4mo ago

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than nat…

Twilightqt · qtdeclarativeEPSS 0.22%via NVD
CVE-2025-5683Medium· 5.5
1y ago

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.

Sunlitqt · qtEPSS 0.23%via NVD
qt vulnerabilities (CVEs) · VulnSea