Logo
vulnerabilityCVE-2025-5455
Name
CVE-2025-5455
Source
NVD ( link)Debian ( link)
Description
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
qt5base
Exploitable
qt6base
Exploitable

Vulnerability Ratings#


8.4
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
bebdfd54917e25d1c100e6bd9f5dd53c2e645fd8
Exploitable
buildroot
2025.02.x
6.8.4
Not Affected