Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15037

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

A flaw was found in Qt XML. This vulnerability, categorized as improper output neutralization, allows an attacker to inject arbitrary XML (Extensible Markup Language) markup. This occurs because the QDom component, when serializing comments, CDATA (Character Data), and processing instructions, does not properly escape node terminators under its default invalid data policy. Consequently, untrusted text processed by an application can lead to the injection of malicious XML, potentially compromising data integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesqt5Affected
Red Hat Hardened Imagesqt6Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-91
https://bugzilla.redhat.com/show_bug.cgi?id=2506397qt: Qt XML: XML injection via improper output neutralization in QDom serialization.

EPSS

Процентиль: 18%
0.00262
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

nvd
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

msrc
4 дня назад

XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization

debian
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, ...

github
19 дней назад

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

EPSS

Процентиль: 18%
0.00262
Низкий

5.3 Medium

CVSS3