CVE-2026-19395: 
Qt Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-19395 is a Denial of Service vulnerability in Qt for MCUs affecting the styled text rendering component. When a Text element displays styled text containing an <img> tag with an attribute that has an empty value, the text parser passes the empty value to an internal check that only accepts non-empty values; the check fails, triggers an error, and the default error handler halts the device. The affected versions are Qt for MCUs 2.12.0 through 2.12.2 (fixed in 2.12.3). It carries a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory).

Détails techniques

The root cause is classified under CWE-230 (Improper Handling of Missing Values) and CWE-617 (Reachable Assertion). The Qt for MCUs text parser does not validate whether attribute values within <img> tags in styled text are non-empty before passing them to an internal validation routine; when an empty value is encountered, the assertion/check fails and the default error handler halts the device. The attack vector is network-based (CVSS AV:N), requires no privileges, no user interaction, and no special attack conditions, making it straightforward to trigger remotely if an attacker can supply styled text input to a vulnerable Text element (GitHub Advisory).

Impact

Successful exploitation results in a complete device halt, causing a full loss of availability for the affected MCU-based device. There is no impact on confidentiality or integrity. Because Qt for MCUs is typically deployed in embedded and IoT contexts (e.g., industrial controls, automotive HMIs, consumer electronics), a device halt can have significant operational consequences depending on the deployment environment (GitHub Advisory).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. NVD SSVC assessment notes the vulnerability is automatable (no manual steps required per exploitation attempt) but exploitation has not been observed (GitHub Advisory).

Étapes d’exploitation

  1. Identify target: Locate a device running Qt for MCUs versions 2.12.0–2.12.2 that renders styled text from external or user-controlled input in a Text element.
  2. Craft malicious payload: Construct a styled text string containing an <img> tag with at least one attribute set to an empty value, e.g., <img src=""/> or <img alt=""/>.
  3. Deliver payload: Supply the crafted styled text to the vulnerable Text element via any available input channel (e.g., network-delivered content, user input field, remote configuration).
  4. Trigger device halt: The Qt for MCUs text parser processes the <img> tag, passes the empty attribute value to the internal non-empty check, which fails and invokes the default error handler, halting the device (GitHub Advisory).

Indicateurs de compromis

  • Device Behavior: Unexpected device halt or freeze occurring after rendering styled text content containing <img> tags.
  • Logs: Error log entries from the Qt for MCUs runtime indicating a failed internal assertion or value check related to text/image attribute parsing, if logging is enabled on the device.
  • Network: Unusual or repeated delivery of styled text payloads containing <img> tags with empty attributes to the device's input interfaces.

Atténuation et solutions de contournement

Qt has released a patch in Qt for MCUs version 2.12.3, which resolves this vulnerability. Users should upgrade to version 2.12.3 or later as the primary remediation. As a workaround where upgrading is not immediately possible, implement input validation to sanitize all styled text before it is passed to Text elements, ensuring no <img> tags contain attributes with empty values (GitHub Advisory, Qt Advisory).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Qt Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19395MEDIUM6.6
  • Qt logoQt
  • qt6
NonNonOct 05, 2026
CVE-2026-76151MEDIUM4.6
  • Qt logoQt
  • qt5-qtbase
NonOuiSep 16, 2026
CVE-2026-79680MEDIUM4.5
  • Qt logoQt
  • cpe:2.3:a:qt:qt
NonOuiSep 24, 2026
CVE-2026-78253LOW2.3
  • Qt logoQt
  • qt6.src
NonOuiSep 23, 2026
CVE-2026-79616LOW0.6
  • Qt logoQt
  • qt5-qtdeclarative-examples
NonOuiSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités