Description
An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and Limited Memory Disclosure
Action: Assess Impact
AI Analysis

Impact

An out‑of‑bounds read in Qt NFC's language code length parser allows a physically proximate attacker to read memory between a bounded and an unbounded length, potentially revealing data and triggering a denial of service. The vulnerability, classified as CWE‑125 and CWE‑191, corrupts program state or exposes data but does not permit arbitrary code execution.

Affected Systems

Qt’s NFC module is affected, specifically the QNdefNfcTextRecord handling within the Qt Qt library. Version information is not specified in the CVE vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates medium to high severity. EPSS information is not available and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet. The attack likely requires an attacker to present a crafted NFC tag to a device that actively scans NFC tags, meaning physical proximity is necessary to cause a denial of service or disclose limited memory.

Generated by OpenCVE AI on September 11, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Qt to a version that fixes the QNdefNfcTextRecord vulnerability once the vendor releases an update.
  • If no patch is immediately available, disable the NFC feature on devices that do not need it, or limit access to it through proper authentication or wh devices that use NFC to prevent unauthorized tags from being presented within range.
  • As a temporary countermeasure, implement additional validation of NFC data using application‑level checks to detect malformed tags before processing, or restrict NFC usage to trusted devices only.

Generated by OpenCVE AI on September 11, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.
Title Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module
First Time appeared Qt
Qt qt
Weaknesses CWE-125
CWE-191
CPEs cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
Vendors & Products Qt
Qt qt
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Qt

Published:

Updated: 2026-09-11T12:08:24.776Z

Reserved: 2026-06-25T12:20:33.980Z

Link: CVE-2026-13326

cve-icon Vulnrichment

Updated: 2026-09-11T12:08:21.237Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T07:16:45.620

Modified: 2026-09-18T19:21:34.307

Link: CVE-2026-13326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:00:15Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)