Impact
Uncontrolled recursion (CWE‑674) occurs in Qt's XML serialization path when QDomElementPrivate::save() and QDomNodePrivate::save() call each other recursively without a depth limit or error return. Each nested element consumes one stack frame, so a document with deep nesting will parse but when serialized (for example with QDomDocument::toByteArray or QDomDocument::toString) the stack overflows, causing the process to terminatetrusted XML or SVG document and results in a denial of service; there is no code execution or memory disclosure.
Affected Systems
The issue is present in Qt (the QtXml component). Any installation of the Qt framework that employs QDomDocument::toByteArray for parsing SVG or other XML content is affected; no specific version numbers are supplied, so all current Qt releases that use this method may be vulnerable.
Risk and Exploitability
The severity is medium‑to‑high with a CVSS score of 7.1. The EPSS score is below 1%, indicating a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It can be triggered via any untrusted XML or SVG input, so the likely attack vector is remote delivering malformed files to a Qt‑powered application. While no public exploits exist, the widespread deployment of Qt makes this denial of service a significant concern if unpatched.
OpenCVE Enrichment