CVE-2026-76151: 
Qt Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-76151 is an out-of-bounds read (buffer over-read) vulnerability in the HTTP Cache-Control response header parsing within the QtNetwork module of Qt. It affects Qt versions 6.0.0 through 6.8.8 and 6.9.0 through 6.11.1, and can be triggered by a remote attacker via an excessively large Cache-Control header value returned by an untrusted or compromised HTTP server to an application using QNetworkAccessManager. Only the client side of the connection is affected; 32-bit builds are not vulnerable. The vulnerability carries a CVSS v4.0 base score of 4.6 (Medium) (Qt Advisory).

Détails techniques

The root cause is an out-of-bounds read (CWE-125) combined with a numeric truncation error (CWE-197) during parsing of the HTTP Cache-Control response header in Qt's QtNetwork module. When a server returns an excessively large header value, the parser reads beyond the intended buffer boundary on 64-bit builds. The access is strictly read-only — no data is written out of bounds — meaning there is no information disclosure and no code execution possible; the only consequence is an application crash (denial of service). A fix is available in the Qt source repository (Qt Code Review).

Impact

Successful exploitation causes a denial of service via application crash in any Qt 6 application (64-bit builds) that uses QNetworkAccessManager to communicate with untrusted or attacker-controlled HTTP servers. There is no confidentiality or integrity impact, as the out-of-bounds access is read-only with no information disclosure and no code execution. The blast radius is limited to the affected client application; lateral movement and data exfiltration are not applicable to this vulnerability (Qt Advisory).

Exploitabilité

There is no known public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The CVSS v4.0 assessment marks exploit maturity as "Unreported" and the NVD SSVC assessment confirms exploitation status as "none" and the vulnerability as non-automatable. The EPSS score is approximately 0.64%, indicating a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified (Qt Advisory).

Étapes d’exploitation

  1. Set up a malicious HTTP server: Configure an HTTP server under attacker control to return a response with an excessively large Cache-Control header value (e.g., a header value of several gigabytes or crafted to exceed the parser's expected bounds on 64-bit systems).
  2. Lure or position the target: Direct a vulnerable Qt 6 application (64-bit build, versions 6.0.0–6.8.8 or 6.9.0–6.11.1) to make an HTTP request to the attacker-controlled server — for example, via a man-in-the-middle attack on an unencrypted connection, DNS poisoning, or by hosting a malicious resource linked from a legitimate context.
  3. Trigger the vulnerability: When the application's QNetworkAccessManager processes the HTTP response, the oversized Cache-Control header triggers the out-of-bounds read in the QtNetwork parsing code.
  4. Achieve denial of service: The out-of-bounds read causes the application to crash, resulting in a denial of service for the affected client (Qt Advisory, Qt Code Review).

Indicateurs de compromis

  • Network: Unexpected HTTP responses from servers containing abnormally large or malformed Cache-Control header values; traffic to unfamiliar or newly observed IP addresses/domains from Qt-based applications.
  • Logs: Application crash logs or core dumps originating from Qt-based processes, particularly referencing QNetworkAccessManager or QtNetwork-related stack frames; OS-level crash reports (e.g., Windows Event Log application errors, Linux dmesg segfault entries) tied to Qt applications.
  • Process: Unexpected termination of Qt-based client applications following HTTP requests to external servers.

Atténuation et solutions de contournement

Qt has released patched versions addressing this vulnerability: 6.8.9 (for the 6.0.0–6.8.x branch) and 6.11.2 (for the 6.9.0–6.11.x branch). Users should upgrade to these versions as the primary remediation. As a temporary workaround where upgrading is not immediately possible, restricting Qt applications to communicate only with trusted, controlled HTTP servers reduces exposure. Note that 32-bit builds are not affected and do not require remediation (Qt Advisory, Qt Code Review).

Réactions de la communauté

The Qt Group published an official security advisory promptly upon disclosure. Community discussion was observed on programming.dev, reflecting general awareness among Qt developers. No significant independent researcher commentary or major media coverage has been identified, consistent with the vulnerability's moderate severity and limited impact scope.

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

bookworm

qtbase-opensource-src

Fixe

sid

qtbase-opensource-src

Fixe

trixie

qtbase-opensource-src

Fixe

Ubuntu

Inconnu

bionic (esm-infra)

qtbase-opensource-src

Inconnu

devel

qt6-base

Inconnu

focal (esm-apps)

qtbase-opensource-src

Inconnu

jammy

qt6-base

Inconnu

jammy (esm-apps)

qt6-base

Inconnu

noble

qt6-base

Inconnu

noble (esm-apps)

qt6-base

Inconnu

resolute

qt6-base

Inconnu

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Qt Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19395MEDIUM6.6
  • Qt logoQt
  • qt6
NonNonOct 05, 2026
CVE-2026-76151MEDIUM4.6
  • Qt logoQt
  • qt5-qtbase
NonOuiSep 16, 2026
CVE-2026-79680MEDIUM4.5
  • Qt logoQt
  • cpe:2.3:a:qt:qt
NonOuiSep 24, 2026
CVE-2026-78253LOW2.3
  • Qt logoQt
  • qt6.src
NonOuiSep 23, 2026
CVE-2026-79616LOW0.6
  • Qt logoQt
  • qt5-qtdeclarative-examples
NonOuiSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités