PT-2026-63979 · Qt Company · Qt Xml
CVE-2026-15037
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Qt XML versions 4.0.0 through 6.11
Description
Improper output neutralization in QDom comment, CDATA, and processing-instruction serialization allows untrusted text to inject arbitrary XML markup. This occurs because node terminators are not escaped when using the default
InvalidDataPolicy (AcceptInvalidChars).Recommendations
Update to version 6.12.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qt Xml