Junglewise Threat Intelligence

CVE-2025-14575: Qt Framework uncontrolled search path in Qt Network OpenSSL backend

CVE-2025-14575 · Severity: info · CVSS 1.8 · Published 2026-05-19

Vendors: Qt Group.

Executive brief

A vulnerability in the Qt Framework, a widely used software development toolkit, could allow a local attacker to compromise secure network connections on Unix-based systems. By placing a malicious file in a specific folder, an attacker can trick applications into trusting a fake security certificate. This could allow the attacker to intercept or manipulate encrypted data that the application assumes is secure.

Technical details

An Uncontrolled Search Path Element (CWE-427) vulnerability exists in the OpenSSL TLS backend of Qt Network (qtbase) on Unix platforms. The issue stems from the application incorrectly searching the current working directory for certificate files when initializing the OpenSSL backend. A local attacker with the ability to place files in the application's working directory can provide a crafted certificate file that the application will treat as a trusted system Certificate Authority (CA). This allows for the bypass of standard certificate validation, potentially enabling man-in-the-middle attacks against TLS traffic generated by the affected Qt application. A fix has been identified in the Qt Project code review system.

Affected products

  • Qt Group Qt Framework (qtbase) Unix platforms

Timeline

  • 2026-05-19: disclosed: Initial NVD publication

References