CVE-2025-5455 — Improper Input Validation in Qt6-base
Severity
8.4HIGHNVD
EPSS
0.4%
top 40.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateJun 10
Description
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.
If the function was called with malformed data, for example, an URL that
contained a "charset" parameter that lacked a value (such as
"data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).
This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This…
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Affected Packages6 packages
🔴Vulnerability Details
2OSV▶
CVE-2025-5455: An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user↗2025-06-02
GHSA▶
GHSA-5cfg-qhv9-4842: An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user↗2025-06-02
📋Vendor Advisories
3Microsoft
▶
Debian▶
CVE-2025-5455: qt6-base - An issue was found in the private API function qDecodeDataUrl() in QtCore, which...↗2025