CVE-2026-15037

EUVD-2026-48254
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TQtCCNA
2.9 LOW
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 17.87%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qtqt
4.0.0 ≤
𝑥
< 6.12.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
qt6-base
bookworm
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
qtbase-opensource-src
bookworm
postponed
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt4-x11
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
qt6-base
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
qtbase-opensource-src
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
qtbase
Azure Linux 3.0
0:6.6.3-5.azl3
fixed