Remote Denial-of-Service Vulnerability in QDomDocument XML Parsing by Qt Project
CVE-2026-19248

7.1HIGH

Key Information:

Vendor

Qt

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-19248?

The QDomDocument component within the Qt Project is susceptible to a remotely-triggered denial-of-service condition when processing untrusted XML input. This vulnerability may allow an attacker to craft specific malicious input that could crash the application, effectively disrupting service and impacting user experience. Proper input validation and sanitization measures should be implemented to mitigate the risks associated with this vulnerability. For more insights, see this dev patch.

Affected Version(s)

qt 2.2.0 <= 6.8.8

qt 6.9.0 <= 6.11.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.