Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A document with deeply nested elements parses successfully but exhausts the call stack and terminates the process when serialized. Reachable via QDomDocument::toByteArray() (Qt 4.0 and later), QDomDocument::toString(), QDomDocument::toCString(), QDomNode::save(), and operator<<(QTextStream&, const QDomNode&). Denial of service only — no code execution and no memory disclosure. |
| Title | QDomDocument::toByteArray() crashes when parsing svg file | Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml) |
Wed, 09 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-776 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 08 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted XML crash the app via stack exhaustion (DoS only). | |
| Title | QDomDocument::toByteArray() crashes when parsing svg file | |
| First Time appeared |
Qt
Qt qt |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qt
Qt qt |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Qt
Published:
Updated: 2026-09-11T09:31:34.532Z
Reserved: 2026-06-08T10:01:44.921Z
Link: CVE-2026-11573
Updated: 2026-09-08T13:48:58.466Z
Status : Deferred
Published: 2026-09-08T13:17:17.007
Modified: 2026-09-11T10:16:50.500
Link: CVE-2026-11573
OpenCVE Enrichment
Updated: 2026-09-11T10:30:09Z