
PEACH
Un cadre d’isolation des locataires
CVE-2026-78253 is a denial-of-service vulnerability caused by uncontrolled recursion in the QXmlStreamReader::readElementText() function in Qt Group's Qt framework. An attacker can trigger application crashes via stack exhaustion by supplying a crafted XML document to any application that processes untrusted XML using the affected Qt API. Affected versions span Qt 5.0.0 through 6.8.8 and Qt 6.9.0 through 6.11.1. The vulnerability was published on September 23, 2026, and carries a CVSS v3.1 base score of 4.7 (Medium) and a CVSS v4.0 base score of 2.3 (Low) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-674 (Uncontrolled Recursion) and CWE-776 (Improper Restriction of Recursive Entity References in DTDs). The QXmlStreamReader::readElementText() function does not impose adequate limits on recursion depth when parsing deeply nested XML elements, allowing a specially crafted XML document to exhaust the call stack and crash the host application. Exploitation requires user interaction (e.g., an application opening or processing a malicious XML file) and is not automatable. A patch commit is publicly referenced at the Qt code review platform (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation results in an application crash (stack exhaustion), causing a complete loss of availability for the affected process. There is no impact on confidentiality or integrity, and the vulnerability does not enable lateral movement or data exfiltration. Any Qt-based application that parses untrusted XML input — including desktop, server-side, or embedded applications — is potentially affected across the broad range of Qt 5.x and 6.x versions (Red Hat Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the NVD SSVC assessment confirms exploitation status as "none." The EPSS score is approximately 0.253% (15th percentile), indicating a low near-term exploitation probability. Exploitation is not automatable and requires user interaction, further limiting practical attack scenarios (GitHub Advisory, Red Hat Advisory).
<a><a><a>...</a></a></a>) designed to trigger unbounded recursion in QXmlStreamReader::readElementText().QXmlStreamReader to parse untrusted input — for example, by sending it as a file attachment, form upload, or network message depending on the application's input surface.QXmlStreamReader::readElementText).Update Qt to a version newer than 6.8.8 (for the 5.x–6.8 branch) or newer than 6.11.1 (for the 6.9+ branch). The upstream fix is tracked in the Qt code review system. As a temporary workaround where patching is not immediately possible, implement input validation to reject or limit XML documents with excessive nesting depth before they reach the Qt parser. Prioritize patching applications that process untrusted or externally supplied XML documents in production environments (Red Hat Advisory, Qt Security Advisory).
Qt Group published an official security advisory on their blog at the time of disclosure. Red Hat tracked the issue via Bugzilla and assigned it medium severity for their product lines. No significant independent researcher commentary or broad social media discussion has been observed, consistent with the vulnerability's low severity rating and lack of known exploitation (Qt Security Advisory, Red Hat Bugzilla).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bookworm
qtbase-opensource-src
sid
qtbase-opensource-src
trixie
qtbase-opensource-src
bionic (esm-infra)
qtbase-opensource-src
devel
qt6-base
focal (esm-apps)
qtbase-opensource-src
jammy
qt6-base
jammy (esm-apps)
qt6-base
noble
qt6-base
noble (esm-apps)
qt6-base
resolute
qt6-base
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."