Denial of Service Vulnerability in QtCore Affecting Multiple Versions of Qt Framework
CVE-2025-5455
What is CVE-2025-5455?
A flaw in the private API function qDecodeDataUrl() in QtCore affects certain versions of the Qt Framework, particularly impacting QTextDocument and QNetworkReply. When this function is mishandled with malformed data, such as a URL that includes a 'charset' parameter without a value, it triggers an assertion failure, leading to an unexpected application abort. This vulnerability can be exploited to execute denial of service attacks, disrupting application availability. The issue has been addressed in the latest updates of Qt Framework, including versions 5.15.19, 6.5.9, 6.8.4, and 6.9.1, highlighting the importance of upgrading to secure systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Qt 0 <= 5.15.18
Qt 6.0.0 <= 6.5.8
Qt 6.6.0 <= 6.8.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
