CVE-2025-10728Uncontrolled Recursion in Qt6-svg

Severity
9.4CRITICALNVD
EPSS
0.0%
top 99.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 3
Latest updateOct 14

Description

When the module renders a Svg file that contains a element, it might end up rendering it recursively leading to stack overflow DoS

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P

Affected Packages5 packages

debiandebian/qt6-svg< qt6-svg 6.9.2-3 (forky)
debiandebian/qtsvg-opensource-src< qt6-svg 6.9.2-3 (forky)
CVEListV5the_qt_company/qt6.7.06.8.4+1

🔴Vulnerability Details

2
GHSA
GHSA-x6f6-j278-6544: When the module renders a Svg file that contains a element, it might end up rendering it recursively leading to stack overflow DoS2025-10-03
OSV
CVE-2025-10728: When the module renders a Svg file that contains a element, it might end up rendering it recursively leading to stack overflow DoS2025-10-03

📋Vendor Advisories

3
Microsoft
Uncontrolled recursion in Qt SVG module2025-10-14
Red Hat
qtsvg: Uncontrolled recursion in Qt SVG module2025-10-03
Debian
CVE-2025-10728: qt6-svg - When the module renders a Svg file that contains a <pattern> element, it might e...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
CVE-2025-10728 — Uncontrolled Recursion in Qt6-svg | cvebase