Impact
A parsing bug in Qt's QDomNode destructor causes unbounded recursion when handling malformed XML. The bug can lead to a stack overflow that crashes the process, making the application unavailable to users. Attackers can trigger the crash remotely by sending crafted XML to any component reliant on Qt XML parsing.
Affected Systems
Qt libraries used in desktop and embedded applications. The vulnerability affects any product that includes the vulnerable Qt XML module; no specific version range is published, so all installations that have not applied the latest Qt base update are potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. EPSS is not available, suggests this issue has not been widely exploited yet. However, attackers can target the vulnerable component from outside by supplying malicious XML No special privileges or local access are required for exploitation.
OpenCVE Enrichment