Text Element Vulnerability in Qt for MCUs from The Qt Company
CVE-2026-19395

6.6MEDIUM

Key Information:

Vendor

Qt

Vendor
CVE Published:
5 October 2026

What is CVE-2026-19395?

In Qt for MCUs, a vulnerability exists in the text element that handles styled text. When an tag within the styled text contains an attribute with an empty value, the text parser incorrectly processes this, leading to a failure in an internal check that expects only non-empty values. As a result, the system triggers an error, activating the default error handler which subsequently halts the device operation, impacting functionality and user experience.

Affected Version(s)

Qt for MCUs 2.12.0 < 2.12.3

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.