A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253. [cid:ec719d4e-aed1-44be-a0fb-98353e0b04a2] Affected versions: From Qt 5.0 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1
Impact: When a deeply nested XML document is passed to QXmlStreamReader::readElementText(), the recursive parsing can exhaust the call stack and crash the application, even for moderately sized inputs. Such documents may originate from untrusted sources, for example via XMLHttpRequest in QML or data fetched with QNetworkAccessManager. CVSS 4.0 Score: 2.3 / Low Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/RE:L/U:Green Mitigation: Count and restrict the nesting level of XML documents before parsing them with QXmlStreamReader. Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2, or later. Patches: dev: https://codereview.qt-project.org/c/qt/qtbase/+/754345 Qt 6.11: https://codereview.qt-project.org/c/qt/qtbase/+/756741 or https://download.qt.io/official_releases/qt/6.11/CVE-2026-78253-qtbase-6.11.diff Qt 6.10: https://codereview.qt-project.org/c/qt/qtbase/+/763174 or https://download.qt.io/official_releases/qt/6.10/CVE-2026-78253-qtbase-6.10.diff Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/756872 or https://download.qt.io/official_releases/qt/6.8/CVE-2026-78253-qtbase-6.8.diff Tero Pelkonen Qt Group Confidential
_______________________________________________ Announce mailing list [email protected] https://lists.qt-project.org/listinfo/announce
-- Development mailing list [email protected] https://lists.qt-project.org/listinfo/development
