Description
In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
Published: 2026-10-05
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Qt for MCUs has a text rendering flaw in which a <img> tag that contains an attribute with an empty value causes the internal parser to report an error and the default error handler to halt the device. The flaw is an example of improper handling of malformed input (CWE‑230) that leads to denial of service. An attacker who can provide styled text to the device, such as through a GUI or an API, can trigger the halt, disrupting availability of the affected firmware.

Affected Systems

The vulnerability affects all versions of Qt for MCUs that include the Text element used for styled text rendering. No specific version range is listed, so the risk applies broadly to any installation of Qt for MCUs that has not applied a vendor fix.

Risk and Exploitability

The CVSS score of 6.6 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity. However, because the flaw can be triggered by user‑supplied styled text, the likely attack vector is any user or remote interface that allows styled text input. If an attacker can supply malformed <img> tags, the device will halt, leading to a denial of service. The lack of a pre‑check for empty attribute values and the default error handler that halts the system make the flaw straightforward to exploit once the input vector is available.

Generated by OpenCVE AI on October 5, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched release of Qt for MCUs that includes the fixed parser check
  • Sanitize or validate styled text input to strip <img> tags with empty attribute values before rendering
  • If styled text is optional, disable the Text element’s styled rendering or provide a custom error handler that does not halt the system

Generated by OpenCVE AI on October 5, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
Description In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
Title An empty <img> attribute value in styled text triggers a parser error that halts the device.
First Time appeared Qt
Qt qt For Mcus
Weaknesses CWE-230
CWE-617
CPEs cpe:2.3:a:qt:qt_for_mcus:*:*:*:*:*:*:*:*
Vendors & Products Qt
Qt qt For Mcus
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Qt

Published:

Updated: 2026-10-05T12:04:27.598Z

Reserved: 2026-08-10T07:19:46.149Z

Link: CVE-2026-19395

cve-icon Vulnrichment

Updated: 2026-10-05T12:04:10.460Z

cve-icon NVD

Status : Received

Published: 2026-10-05T10:16:41.923

Modified: 2026-10-05T13:16:53.073

Link: CVE-2026-19395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-230

    Improper Handling of Missing Values

  • CWE-617

    Reachable Assertion