Impact
An excessive Cache-Control header value sent by an untrusted HTTP server can cause a client-side out‑of‑bounds read in QtNetwork’s header parser. The read is read‑only and does not leak data or allow code execution, but it crashes the application, resulting in a denial of service.
Affected Systems
The Qt Framework (QtNetwork module) version 6.0.0 through 6.8.8 and 6.9.0 through 6.11.1 are vulnerable on 64‑bit builds. The Qt product "qt:qt" is affected; 32‑bit builds are not impacted.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate risk, with an EPSS score below 1% showing that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog. Attacks require only that the victim receive a large Cache‑Control header from an HTTP server; no privileged access or special interaction is required. The impact is limited to crashing the client application.
OpenCVE Enrichment