A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253.
A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253.
Affected versions: From Qt 5.0 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1
Impact: When a deeply nested XML document is passed to QXmlStreamReader::readElementText(), the recursive parsing can exhaust the call stack and crash the application, even for moderately sized inputs. Such documents may originate from untrusted sources, for example via XMLHttpRequest in QML or data fetched with QNetworkAccessManager.
CVSS 4.0 Score: 2.3 / Low
Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/RE:L/U:Green
Mitigation: Count and restrict the nesting level of XML documents before parsing them with QXmlStreamReader.
Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2, or later.

Out-of-bounds read vulnerability in the Qt Quick Context2D.path and..

An out-of-bounds read (buffer over-read) vulnerability in the HTTP..
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick | 0 | 9.21 | 23-09-2026 |
| 2 | Oracle Security Alert Advisory - CVE-2026-35273 | 0 | 10 | 11-06-2026 |
| 3 | SUSE 2026-2731-1 editorconfig-core-c Moderate Stack Overflow Threat | 0 | 5 | 03-07-2026 |
| 4 | SUSE jq Moderate Policy Bypass and Stack Overflow Fix 2026-23735-1 | 0 | 10 | 21-09-2026 |
| 5 | SUSE glibc Moderate Buffer Overflow Vulnerability 2026-23738-1 | 0 | 10 | 21-09-2026 |
| 6 | KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window" | -2 | 7 | 02-07-2026 |
| 7 | CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path | 0 | 7.54 | 20-05-2026 |
| 8 | Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay | 0 | 15 | 28-07-2026 |
| 9 | Rust Issues Warning Over Key Developers Being Targeted For Compromise | 0 | 6.4 | 17-09-2026 |
| 10 | Attackers Exploit N-able Patch Bypass Flaw on RMM Servers | 0 | 11.23 | 03-08-2026 |