Out-of-Bounds Read in QtNetwork Module Affects Qt Group Software
CVE-2026-76151

4.6MEDIUM

Key Information:

Vendor

Qt

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-76151?

An out-of-bounds read in the HTTP Cache-Control header parsing within the QtNetwork module can lead to application crashes when processing oversized header values from untrusted HTTP servers. This vulnerability primarily affects client-side applications using QNetworkAccessManager and is relevant to both recent and earlier versions of Qt. Specifically, 32-bit builds are not susceptible, while the impact is isolated to read-only access without the risk of code execution or information disclosure.

Affected Version(s)

qt 6.0.0 < 6.8.9

qt 6.9.0 < 6.11.2

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.