Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

qt — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in qt, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the QT software product developed by The Qt Company. It aggregates reported security flaws and configuration errors identified within the QT ecosystem, covering vulnerability data from early 2010s through recent updates in 2024. Visitors to this resource can track vendor security advisories for specific QT components, understand the prevalence and impact of specific weakness classes within this framework, and look up the historical vulnerability record for individual releases or modules. By centralizing this information, the page serves as a reference point for developers, security analysts, and system administrators seeking to assess the risk profile of QT-based applications. The collection includes details on input validation issues, memory corruption defects, and improper access controls, reflecting the diverse attack surface inherent in complex multimedia and UI development kits. Users can explore how certain weakness types manifest across different versions, aiding in prioritization of patches and mitigation strategies. This aggregation does not provide remediation advice but rather offers a factual overview of known security issues. It is designed to facilitate informed decision-making regarding software updates and architecture reviews. The data is sourced from public vulnerability databases and vendor announcements, ensuring transparency and accuracy for the security community.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-11573 QDomDocument::toByteArray() crashes when parsing svg file CWE-674 7.1 High 2026-09-08
CVE-2026-15037 XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization CWE-91 2.9 Low 2026-07-23
CVE-2026-9499 Out-of-bounds read in QTextCodec::codecForName() in Qt CWE-125 - - 2026-07-21
CVE-2025-14575 Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading CWE-427 1.8 Low 2026-05-19
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash CWE-843 8.7 High 2026-05-06
CVE-2025-14576 Possible QML code injection in VectorImage component CWE-94 7.4 High 2026-04-30
CVE-2025-12385 Improper validation of <img> tag size in Text component parser CWE-770 8.7 High 2025-12-03
CVE-2025-23050 Qt 缓冲区错误漏洞 CWE-125 3.1 Low 2025-10-31
CVE-2025-6338 Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend CWE-459 9.2 Critical 2025-10-16
CVE-2025-10729 Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG CWE-416 9.4 Critical 2025-10-03
CVE-2025-10728 Uncontrolled recursion in Qt SVG module CWE-674 9.4 Critical 2025-10-03
CVE-2025-5992 Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service CWE-20 2.3 Low 2025-07-11
CVE-2025-5991 Use after free in QHttp2ProtocolHandler CWE-416 2.1 Low 2025-06-11
CVE-2025-5683 Qt 安全漏洞 5.1 Medium 2025-06-05
CVE-2025-5455 Possible denial of service when passing malformed data in a URL to qDecodeDataUrl CWE-20 8.4 High 2025-06-02
CVE-2025-4211 Improper Link Resolution Before File Access in QFileSystemEngine on Windows CWE-59 7.3 High 2025-05-16
CVE-2025-3512 Buffer overflow in QTextMarkdownImporter CWE-122 4.8 Medium 2025-04-11
CVE-2025-30348 Qt 安全漏洞 CWE-407 5.8 Medium 2025-03-21
CVE-2022-40983 Qt 输入验证错误漏洞 CWE-190 8.8 - 2023-01-12
CVE-2022-43591 Qt 安全漏洞 CWE-122 8.8 - 2023-01-12
CVE-2021-3481 Libqt 缓冲区错误漏洞 CWE-125 7.1 - 2022-08-22

All 21 known CVE vulnerabilities affecting qt with full Chinese analysis, references, and POCs where available.