Skip to content
Qt Group PlcCVE-2026-15037

Improper output neutralization

Low2.9CVE-2026-15037 · Published Jul 23, 2026

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

Qt Group Plc advisory

Affected versions

PackageAffectedFixed in
Qt
Product
>= 4.0.0, < 6.12.06.12.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-91

More Qt Group Plc advisories

All Qt Group Plc
Advisory
qt: denial of service
High7.1Sep 16
qt: out-of-bounds read
Medium6.9Sep 11
qt: denial of service
High7.1Sep 8
Qt: out-of-bounds read
Medium6.3Jul 21
Qt Group Plc Axivion: open redirect
Medium6.8Jul 16
Qt Group Plc Axivion: missing authorization
High8.7Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.