An XML injection (improper output neutralization) vulnerability in the Qt 
XMLQDom comment, CDATA section, and processing-instruction serialization of the 
Qt Framework (QtXml module) has been discovered and has been assigned the CVE 
id CVE-2026-15037.

Affected versions: all Qt 4 and Qt 5 and Qt 6 releases before Qt 6.12 (default 
QDomImplementation::InvalidDataPolicy of AcceptInvalidChars).

Impact: An application that inserts untrusted text into a QDom comment, CDATA 
section, or processing-instruction node and then serializes the document may 
emit XML in which the untrusted text closes the intended node and injects 
attacker-controlled sibling markup, corrupting the structure of the produced 
document. There is no impact on confidentiality and no code execution or 
denial-of-service within Qt itself.

CVSS 4.0 Score: 2.9 (LOW)

Vector 
String:CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Mitigation: On all affected versions, set the invalid-data policy before 
building 
documents:QDomImplementation::setInvalidDataPolicy(QDomImplementation::ReturnNullNode);
 (or DropInvalidChars). With ReturnNullNode, the QDom factory functions return 
a null node when given data that is invalid per XML 1.0 — check the return 
value. As additional defence-in-depth, validate untrusted input before 
inserting it and do not treat QDom output as trusted structure downstream.

Solution: Update to Qt 6.12 or later, where the default InvalidDataPolicy is 
ReturnNullNode. On Qt 6.11 and earlier the default is unchanged; apply the 
mitigation above.

Patches:
dev: 
https://codereview.qt-project.org/c/qt/qtbase/+/748323<https://codereview.qt-project.org/c/qt/qtbase/+/748323?utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-97LRPQec4NJUdg0HMxuIBOYJswq2FLfW4JqKFASoM_hE5YyWizzVLPNSJmEOQ0G6q7SITz>



Confidential
_______________________________________________
Announce mailing list
[email protected]
https://lists.qt-project.org/listinfo/announce
-- 
Development mailing list
[email protected]
https://lists.qt-project.org/listinfo/development

Reply via email to