Qt
94 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Qt, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Qt CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 1 |
| 2025-05 | 1 |
| 2025-06 | 3 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 4 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 7 |
Severity
How the 94 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical11
- High27
- Medium39
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Qt.
- CVE-2026-79680Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module—
- CVE-2026-78253Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt—
- CVE-2026-79616Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick—
- CVE-2026-76151Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)—
- CVE-2026-19248Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt—
- CVE-2026-13326Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module—
- CVE-2026-11573Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml)—
- CVE-2026-15037XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization—
- CVE-2026-9499Out-of-bounds read in QTextCodec::codecForName() in Qt—
- CVE-2025-14575Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading—
- CVE-2026-6210Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash—
- CVE-2025-14576Possible QML code injection in VectorImage component7.8
- CVE-2024-33861Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с недостаточной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности5.8
- CVE-2025-12385Improper validation of <img> tag size in Text component parser4.3
- CVE-2025-23050QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.3.1
Product grouping is registry-driven, with AI assist and human review. How it works