Impact
A parsing bug in Qt's QDomNode destructor causes unbounded recursion when handling malformed XML. The bug results from an uncontrolled recursion weakness (CWE-674) and a destructor-related flaw (CWE-776). This can lead to a stack overflow that crashes the process, making the application unavailable to users. Attackers can trigger the crash remotely by sending crafted XML to any component that relies on Qt XML parsing, resulting in a denial-of-service condition.
Affected Systems
Qt libraries used in desktop and embedded applications. The vulnerability affects any product that includes the vulnerable Qt XML module; no specific version range is published, so all installations that have not applied the latest Qt base update are potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% shows a low probability of exploitation, meaning this vulnerability has not been widely exploited yet. This issue does not appear in the CISA KEV catalog. Attackers can target the vulnerable component from outside by supplying malicious XML. No special privileges or local access are required for exploitation.
OpenCVE Enrichment