
PEACH
Un cadre d’isolation des locataires
CVE-2026-76151 is an out-of-bounds read (buffer over-read) vulnerability in the HTTP Cache-Control response header parsing within the QtNetwork module of Qt. It affects Qt versions 6.0.0 through 6.8.8 and 6.9.0 through 6.11.1, and can be triggered by a remote attacker via an excessively large Cache-Control header value returned by an untrusted or compromised HTTP server to an application using QNetworkAccessManager. Only the client side of the connection is affected; 32-bit builds are not vulnerable. The vulnerability carries a CVSS v4.0 base score of 4.6 (Medium) (Qt Advisory).
The root cause is an out-of-bounds read (CWE-125) combined with a numeric truncation error (CWE-197) during parsing of the HTTP Cache-Control response header in Qt's QtNetwork module. When a server returns an excessively large header value, the parser reads beyond the intended buffer boundary on 64-bit builds. The access is strictly read-only — no data is written out of bounds — meaning there is no information disclosure and no code execution possible; the only consequence is an application crash (denial of service). A fix is available in the Qt source repository (Qt Code Review).
Successful exploitation causes a denial of service via application crash in any Qt 6 application (64-bit builds) that uses QNetworkAccessManager to communicate with untrusted or attacker-controlled HTTP servers. There is no confidentiality or integrity impact, as the out-of-bounds access is read-only with no information disclosure and no code execution. The blast radius is limited to the affected client application; lateral movement and data exfiltration are not applicable to this vulnerability (Qt Advisory).
There is no known public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The CVSS v4.0 assessment marks exploit maturity as "Unreported" and the NVD SSVC assessment confirms exploitation status as "none" and the vulnerability as non-automatable. The EPSS score is approximately 0.64%, indicating a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified (Qt Advisory).
Cache-Control header value (e.g., a header value of several gigabytes or crafted to exceed the parser's expected bounds on 64-bit systems).QNetworkAccessManager processes the HTTP response, the oversized Cache-Control header triggers the out-of-bounds read in the QtNetwork parsing code.Cache-Control header values; traffic to unfamiliar or newly observed IP addresses/domains from Qt-based applications.QNetworkAccessManager or QtNetwork-related stack frames; OS-level crash reports (e.g., Windows Event Log application errors, Linux dmesg segfault entries) tied to Qt applications.Qt has released patched versions addressing this vulnerability: 6.8.9 (for the 6.0.0–6.8.x branch) and 6.11.2 (for the 6.9.0–6.11.x branch). Users should upgrade to these versions as the primary remediation. As a temporary workaround where upgrading is not immediately possible, restricting Qt applications to communicate only with trusted, controlled HTTP servers reduces exposure. Note that 32-bit builds are not affected and do not require remediation (Qt Advisory, Qt Code Review).
The Qt Group published an official security advisory promptly upon disclosure. Community discussion was observed on programming.dev, reflecting general awareness among Qt developers. No significant independent researcher commentary or major media coverage has been identified, consistent with the vulnerability's moderate severity and limited impact scope.
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bookworm
qtbase-opensource-src
sid
qtbase-opensource-src
trixie
qtbase-opensource-src
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."