Hi,
The following vulnerability was published for qt6-base.
CVE-2026-15037[0]:
| Improper output neutralization (XML injection) in QDom comment,
| CDATA, and processing-instruction serialization in Qt XML from 4.0.0
| through 6.11 allows untrusted text serialized by an application into
| those nodes to inject arbitrary XML markup, because the node
| terminators are not escaped under the default InvalidDataPolicy
| (AcceptInvalidChars). Fixed in Qt 6.12.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-15037
https://www.cve.org/CVERecord?id=CVE-2026-15037
[1] https://codereview.qt-project.org/c/qt/qtbase/+/748323
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore