qt-group-plcCVE-2026-13326
An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.
Medium6.9CVE-2026-13326 · Published Sep 11, 2026 · updated Sep 18, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| qt Vendor | >= 5.2.0, < 6.8.9 | 6.8.9 |
| >= 6.9.0, < 6.11.2 | 6.11.2 |
Details and references
An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.