Out-of-Bounds Read Vulnerability in Qt Quick's SVG Path Parsing
CVE-2026-79616

0.6LOW

Key Information:

Vendor

Qt

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-79616?

An out-of-bounds read vulnerability exists in the parsing of untrusted SVG path strings within Qt Quick's Context2D.path and PathSvg.path functionalities. This flaw could allow an attacker to exploit the library, resulting in potential exposure of sensitive information or unintended behavior. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

qt 5.10.0 <= 6.8.8

qt 6.9.0 <= 6.11.1

References

CVSS V4

Score:
0.6
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.