CVE-2026-78253: 
Qt Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-78253 is a denial-of-service vulnerability caused by uncontrolled recursion in the QXmlStreamReader::readElementText() function in Qt Group's Qt framework. An attacker can trigger application crashes via stack exhaustion by supplying a crafted XML document to any application that processes untrusted XML using the affected Qt API. Affected versions span Qt 5.0.0 through 6.8.8 and Qt 6.9.0 through 6.11.1. The vulnerability was published on September 23, 2026, and carries a CVSS v3.1 base score of 4.7 (Medium) and a CVSS v4.0 base score of 2.3 (Low) (Red Hat Advisory, GitHub Advisory).

Détails techniques

The root cause is classified as CWE-674 (Uncontrolled Recursion) and CWE-776 (Improper Restriction of Recursive Entity References in DTDs). The QXmlStreamReader::readElementText() function does not impose adequate limits on recursion depth when parsing deeply nested XML elements, allowing a specially crafted XML document to exhaust the call stack and crash the host application. Exploitation requires user interaction (e.g., an application opening or processing a malicious XML file) and is not automatable. A patch commit is publicly referenced at the Qt code review platform (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation results in an application crash (stack exhaustion), causing a complete loss of availability for the affected process. There is no impact on confidentiality or integrity, and the vulnerability does not enable lateral movement or data exfiltration. Any Qt-based application that parses untrusted XML input — including desktop, server-side, or embedded applications — is potentially affected across the broad range of Qt 5.x and 6.x versions (Red Hat Advisory, GitHub Advisory).

Exploitabilité

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the NVD SSVC assessment confirms exploitation status as "none." The EPSS score is approximately 0.253% (15th percentile), indicating a low near-term exploitation probability. Exploitation is not automatable and requires user interaction, further limiting practical attack scenarios (GitHub Advisory, Red Hat Advisory).

Étapes d’exploitation

  1. Craft malicious XML: Create an XML document with deeply nested elements (e.g., thousands of levels of <a><a><a>...</a></a></a>) designed to trigger unbounded recursion in QXmlStreamReader::readElementText().
  2. Deliver the payload: Provide the crafted XML document to a target application that uses Qt's QXmlStreamReader to parse untrusted input — for example, by sending it as a file attachment, form upload, or network message depending on the application's input surface.
  3. Trigger parsing: Cause the application to open and parse the malicious XML file, either through direct user interaction (opening a file) or via an automated processing pipeline.
  4. Achieve denial of service: The recursive parsing exhausts the process stack, causing the application to crash with a stack overflow, resulting in a denial of service (Red Hat Bugzilla, GitHub Advisory).

Indicateurs de compromis

  • Logs: Application crash logs or core dumps referencing stack overflow or segmentation fault originating from Qt XML parsing functions (e.g., QXmlStreamReader::readElementText).
  • Process: Unexpected termination of Qt-based applications immediately after processing an XML file or network-delivered XML content.
  • File System: Presence of unusually structured XML files with extreme nesting depth in application input directories or temporary folders.

Atténuation et solutions de contournement

Update Qt to a version newer than 6.8.8 (for the 5.x–6.8 branch) or newer than 6.11.1 (for the 6.9+ branch). The upstream fix is tracked in the Qt code review system. As a temporary workaround where patching is not immediately possible, implement input validation to reject or limit XML documents with excessive nesting depth before they reach the Qt parser. Prioritize patching applications that process untrusted or externally supplied XML documents in production environments (Red Hat Advisory, Qt Security Advisory).

Réactions de la communauté

Qt Group published an official security advisory on their blog at the time of disclosure. Red Hat tracked the issue via Bugzilla and assigned it medium severity for their product lines. No significant independent researcher commentary or broad social media discussion has been observed, consistent with the vulnerability's low severity rating and lack of known exploitation (Qt Security Advisory, Red Hat Bugzilla).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

bookworm

qtbase-opensource-src

Affecté

sid

qtbase-opensource-src

Affecté

trixie

qtbase-opensource-src

Affecté

Ubuntu

Inconnu

bionic (esm-infra)

qtbase-opensource-src

Inconnu

devel

qt6-base

Inconnu

focal (esm-apps)

qtbase-opensource-src

Inconnu

jammy

qt6-base

Inconnu

jammy (esm-apps)

qt6-base

Inconnu

noble

qt6-base

Inconnu

noble (esm-apps)

qt6-base

Inconnu

resolute

qt6-base

Inconnu

RHEL / CentOS

Affecté

RHEL 8

Non affecté

RHEL 9

Non affecté

RHEL 10

qt6.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Qt Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19395MEDIUM6.6
  • Qt logoQt
  • qt6
NonNonOct 05, 2026
CVE-2026-76151MEDIUM4.6
  • Qt logoQt
  • qt5-qtbase
NonOuiSep 16, 2026
CVE-2026-79680MEDIUM4.5
  • Qt logoQt
  • cpe:2.3:a:qt:qt
NonOuiSep 24, 2026
CVE-2026-78253LOW2.3
  • Qt logoQt
  • qt6.src
NonOuiSep 23, 2026
CVE-2026-79616LOW0.6
  • Qt logoQt
  • qt5-qtdeclarative-examples
NonOuiSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités