Out-of-Bounds Read Vulnerability in Qt Products
CVE-2026-95509

8.8HIGH

Key Information:

Vendor

Qt

Vendor
CVE Published:
29 September 2026

What is CVE-2026-95509?

An out-of-bounds read vulnerability exists in the Qt Framework due to improper buffer size calculations while handling Latin-1 strings. This flaw may lead to unintended memory access and can potentially exploit application logic, resulting in unexpected behavior or data leakage.

Affected Version(s)

Qt for MCUs 2.6.0 < 2.11.3

Qt for MCUs 2.12.0 < 2.12.3

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.