#1149994 qt6-base: CVE-2026-15037

Package:
src:qt6-base
Source:
src:qt6-base
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 05:03:04 UTC
Severity:
normal
Tags:
#1149994#5
Date:
2026-10-05 05:00:44 UTC
From:
To:
Hi,

The following vulnerability was published for qt6-base.

CVE-2026-15037[0]:
| Improper output neutralization (XML injection) in QDom comment,
| CDATA, and processing-instruction serialization in Qt XML from 4.0.0
| through 6.11 allows untrusted text serialized by an application into
| those nodes to inject arbitrary XML markup, because the node
| terminators are not escaped under the default InvalidDataPolicy
| (AcceptInvalidChars). Fixed in Qt 6.12.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15037
https://www.cve.org/CVERecord?id=CVE-2026-15037
[1] https://codereview.qt-project.org/c/qt/qtbase/+/748323

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore