CVE-2026-19395: Qt For Mcus
Medium severity, CVSS 6.6. EPSS: 0.3% chance of exploitation in the next 30 days.
In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
Affected products
- Qt Qt For Mcus: from 2.12.0, before 2.12.3 (fixed in 2.12.3)
Published 2026-10-05. Last modified 2026-10-06.