CVE-2026-19395: Qt For Mcus

Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.

Affected products

  • Qt Qt For Mcus: from 2.12.0, before 2.12.3 (fixed in 2.12.3)

Published 2026-10-05. Last modified 2026-10-06.