CVE-2026-11573: Qt

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A document with deeply nested elements parses successfully but exhausts the call stack and terminates the process when serialized. Reachable via QDomDocument::toByteArray() (Qt 4.0 and later), QDomDocument::toString(), QDomDocument::toCString(), QDomNode::save(), and operator<<(QTextStream&, const QDomNode&). Denial of service only — no code execution and no memory disclosure.

Affected products

  • Qt Qt: from 2.2.0, before 6.8.2 (fixed in 6.8.2)

Published 2026-09-08. Last modified 2026-09-11.