
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
An issue was discovered in the private API function qDecodeDataUrl() in QtCore, which is utilized in QTextDocument and QNetworkReply components. The vulnerability affects Qt versions up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3, and 6.9.0. The issue was disclosed on June 2, 2025 (NVD).
The vulnerability occurs when the qDecodeDataUrl() function is called with malformed data, specifically when processing URLs containing a 'charset' parameter without a value (e.g., 'data:charset,'). When Qt is built with assertions enabled, this malformed input triggers an assertion, resulting in a denial of service condition through application abort. The vulnerability has been assigned a CVSS 4.0 base score of 8.4 (HIGH) with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/R:U/RE:M/U:Clear. The issue has been classified as CWE-20 (Improper Input Validation) (NVD).
When exploited, this vulnerability can lead to a denial of service condition by causing the application to abort when processing specially crafted input. This affects applications using QtCore's text document and network reply functionalities (NVD).
The vulnerability has been fixed in Qt versions 5.15.19, 6.5.9, 6.8.4, and 6.9.1. Users are advised to upgrade to these patched versions to mitigate the issue (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”