Junglewise Threat Intelligence

CVE-2026-78253: Qt stack exhaustion in QXmlStreamReader::readElementText

CVE-2026-78253 · Severity: info · Published 2026-09-23

Vendors: Qt Group.

Executive brief

Qt is a cross-platform development framework used in many desktop and embedded applications. A vulnerability in Qt's XML parsing allows an attacker to crash applications by providing a specially crafted XML document that causes uncontrolled recursion. An application that processes untrusted XML files could be rendered unavailable through this denial of service attack.

Technical details

Uncontrolled recursion in QXmlStreamReader::readElementText() allows stack exhaustion when processing deeply nested XML structures. An attacker can exploit this by sending a crafted XML document to any application using the vulnerable Qt XML parsing API. The attack requires no authentication or user interaction beyond the application processing the malicious XML input; successful exploitation crashes the affected application.

Affected products

  • Qt Group Qt <UNKNOWN>

Timeline

  • 2026-09-23: disclosed

References