CVE-2026-6210

EUVD-2026-27681
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image.



When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-marker element (such as a <line> element) that references itself as a marker triggers an out-of-bounds heap read due to the object size difference between QSvgLine and QSvgMarker,
 followed by an endless recursion that bypasses the marker recursion 
guard through incorrect virtual dispatch. The result is an application 
crash (denial of service).



This issue affects Qt SVG: 
from 6.7.0 before 6.8.8, from 6.9.0 before 6.11.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TQtCCNA
8.7 HIGH
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.08%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qtqt
6.7.0 ≤
𝑥
< 6.8.8
CNA
qtqt
6.9.0 ≤
𝑥
< 6.11.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
qt6-svg
bookworm
no-dsa
forky
6.10.2-9
fixed
sid
6.10.2-9
fixed
trixie
no-dsa
qtsvg-opensource-src
bookworm
no-dsa
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt6-svg
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
qtsvg-opensource-src
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
xenial
not-affected