Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-15037

Опубликовано: 23 июл. 2026
Источник: debian

Описание

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-baseunfixedpackage
qt6-baseno-dsatrixiepackage
qt6-basepostponedbookwormpackage
qtbase-opensource-srcunfixedpackage
qtbase-opensource-srcno-dsatrixiepackage
qtbase-opensource-srcpostponedbookwormpackage
qtbase-opensource-srcpostponedbullseyepackage

Примечания

  • https://codereview.qt-project.org/c/qt/qtbase/+/748323

Связанные уязвимости

ubuntu
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

CVSS3: 5.3
redhat
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

nvd
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

msrc
4 дня назад

XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization

github
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.