CVE-2026-15037

NameCVE-2026-15037
DescriptionImproper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt6-base (PTS)bookworm6.4.2+dfsg-10vulnerable
trixie6.8.2+dfsg-9+deb13u2vulnerable
forky, sid6.10.2+dfsg-15vulnerable
qtbase-opensource-src (PTS)bullseye5.15.2+dfsg-9+deb11u1vulnerable
bullseye (security)5.15.2+dfsg-9+deb11u2vulnerable
bookworm5.15.8+dfsg-11+deb12u3vulnerable
trixie5.15.15+dfsg-6+deb13u1vulnerable
forky, sid5.15.19+dfsg-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt6-basesource(unstable)(unfixed)
qtbase-opensource-srcsource(unstable)(unfixed)

Notes

https://codereview.qt-project.org/c/qt/qtbase/+/748323

Search for package or bug name: Reporting problems