Denial of Service Vulnerability in Qt Group's XML Processing Component
CVE-2026-78253
2.3LOW
What is CVE-2026-78253?
A vulnerability in Qt Group's XML processing component allows attackers to exploit uncontrolled recursion in QXmlStreamReader::readElementText(). By supplying a specially crafted XML document, an attacker can induce a denial of service condition resulting in application crashes due to stack exhaustion. This can compromise the availability of services relying on Qt's XML parsing functionalities, making it crucial for users to address this security risk.
Affected Version(s)
qt 5.0.0 <= 6.8.8
qt 6.9.0 <= 6.11.1
