CVE-2026-78253: Qt

Low severity, CVSS 2.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.

Affected products

  • Qt Qt: from 5.0.0, up to and including 6.8.8; from 6.9.0, up to and including 6.11.1

Published 2026-09-23. Last modified 2026-09-24.