A denial-of-service (stack-exhaustion) vulnerability in the 
QXmlStreamReader::readElementText() function of the XML parsing functionality 
of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253.
[cid:ec719d4e-aed1-44be-a0fb-98353e0b04a2]
Affected versions: From Qt 5.0 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1

Impact: When a deeply nested XML document is passed to 
QXmlStreamReader::readElementText(), the recursive parsing can exhaust the call 
stack and crash the application, even for moderately sized inputs. Such 
documents may originate from untrusted sources, for example via XMLHttpRequest 
in QML or data fetched with QNetworkAccessManager.

CVSS 4.0 Score: 2.3 / Low

Vector String: 
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/RE:L/U:Green

Mitigation: Count and restrict the nesting level of XML documents before 
parsing them with QXmlStreamReader.

Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2, or later.

Patches:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/754345
Qt 6.11: https://codereview.qt-project.org/c/qt/qtbase/+/756741 or 
https://download.qt.io/official_releases/qt/6.11/CVE-2026-78253-qtbase-6.11.diff
Qt 6.10: https://codereview.qt-project.org/c/qt/qtbase/+/763174 or 
https://download.qt.io/official_releases/qt/6.10/CVE-2026-78253-qtbase-6.10.diff
Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/756872 or 
https://download.qt.io/official_releases/qt/6.8/CVE-2026-78253-qtbase-6.8.diff


Tero Pelkonen
Qt Group

Confidential
_______________________________________________
Announce mailing list
[email protected]
https://lists.qt-project.org/listinfo/announce
-- 
Development mailing list
[email protected]
https://lists.qt-project.org/listinfo/development

Reply via email to