CVE-2025-14575: Qt

Low severity, CVSS 1.8. EPSS: 0.1% chance of exploitation in the next 30 days.

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.

Affected products

  • Qt Qt: from 5.0.0, up to and including 5.15.19; from 6.0.0, up to and including 6.5.9; from 6.6.0, up to and including 6.8.3; from 6.9.0, up to and including 6.9.1

Published 2026-05-19. Last modified 2026-07-29.