PT-2026-63979 · Qt Company · Qt Xml

CVE-2026-15037

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Qt XML versions 4.0.0 through 6.11
Description Improper output neutralization in QDom comment, CDATA, and processing-instruction serialization allows untrusted text to inject arbitrary XML markup. This occurs because node terminators are not escaped when using the default InvalidDataPolicy (AcceptInvalidChars).
Recommendations Update to version 6.12.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94116
CVE-2026-15037
ECHO-AC3C-11A6-BE31

Affected Products

Qt Xml