
PEACH
Un cadre d’isolation des locataires
CVE-2026-19395 is a Denial of Service vulnerability in Qt for MCUs affecting the styled text rendering component. When a Text element displays styled text containing an <img> tag with an attribute that has an empty value, the text parser passes the empty value to an internal check that only accepts non-empty values; the check fails, triggers an error, and the default error handler halts the device. The affected versions are Qt for MCUs 2.12.0 through 2.12.2 (fixed in 2.12.3). It carries a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory).
The root cause is classified under CWE-230 (Improper Handling of Missing Values) and CWE-617 (Reachable Assertion). The Qt for MCUs text parser does not validate whether attribute values within <img> tags in styled text are non-empty before passing them to an internal validation routine; when an empty value is encountered, the assertion/check fails and the default error handler halts the device. The attack vector is network-based (CVSS AV:N), requires no privileges, no user interaction, and no special attack conditions, making it straightforward to trigger remotely if an attacker can supply styled text input to a vulnerable Text element (GitHub Advisory).
Successful exploitation results in a complete device halt, causing a full loss of availability for the affected MCU-based device. There is no impact on confidentiality or integrity. Because Qt for MCUs is typically deployed in embedded and IoT contexts (e.g., industrial controls, automotive HMIs, consumer electronics), a device halt can have significant operational consequences depending on the deployment environment (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. NVD SSVC assessment notes the vulnerability is automatable (no manual steps required per exploitation attempt) but exploitation has not been observed (GitHub Advisory).
Text element.<img> tag with at least one attribute set to an empty value, e.g., <img src=""/> or <img alt=""/>.Text element via any available input channel (e.g., network-delivered content, user input field, remote configuration).<img> tag, passes the empty attribute value to the internal non-empty check, which fails and invokes the default error handler, halting the device (GitHub Advisory).<img> tags.<img> tags with empty attributes to the device's input interfaces.Qt has released a patch in Qt for MCUs version 2.12.3, which resolves this vulnerability. Users should upgrade to version 2.12.3 or later as the primary remediation. As a workaround where upgrading is not immediately possible, implement input validation to sanitize all styled text before it is passed to Text elements, ensuring no <img> tags contain attributes with empty values (GitHub Advisory, Qt Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."