Количество 6
Количество 6
CVE-2026-11573
(Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serializ ...)
CVE-2026-11573
Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only).
CVE-2026-11573
Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A document with deeply nested elements parses successfully but exhausts the call stack and terminates the process when serialized. Reachable via QDomDocument::toByteArray() (Qt 4.0 and later), QDomDocument::toString(), QDomDocument::toCString(), QDomNode::save(), and operator<<(QTextStream&, const QDomNode&). Denial of service only — no code execution and no memory disclosure.
CVE-2026-11573
Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml)
CVE-2026-11573
Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serializ ...
GHSA-m72v-p257-4w4p
Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-11573 (Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serializ ...) | 0% Низкий | 3 дня назад | ||
CVE-2026-11573 Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | CVSS3: 7.5 | 0% Низкий | 16 дней назад | |
CVE-2026-11573 Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A document with deeply nested elements parses successfully but exhausts the call stack and terminates the process when serialized. Reachable via QDomDocument::toByteArray() (Qt 4.0 and later), QDomDocument::toString(), QDomDocument::toCString(), QDomNode::save(), and operator<<(QTextStream&, const QDomNode&). Denial of service only — no code execution and no memory disclosure. | 0% Низкий | 16 дней назад | ||
CVE-2026-11573 Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml) | 0% Низкий | 11 дней назад | ||
CVE-2026-11573 Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serializ ... | 0% Низкий | 16 дней назад | ||
GHSA-m72v-p257-4w4p Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | 0% Низкий | 15 дней назад |
Уязвимостей на страницу