CVE-2026-13326: Qt

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

Affected products

  • Qt Qt: from 5.2.0, before 6.8.9 (fixed in 6.8.9); from 6.9.0, before 6.11.2 (fixed in 6.11.2)

Published 2026-09-11. Last modified 2026-09-18.