Skip to main content

Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

Comments

An out-of-bounds read (buffer over-read) vulnerability in the HTTP Cache-Control response header parsing of the Qt Framework (QtNetwork module) has been discovered and has been assigned the CVE id CVE-2026-76151. 

Affected versions:  From Qt 6.0.0 to 6.8.8, From 6.9.0 to 6.11.1 
 
Impact:  An untrusted or compromised HTTP server can cause an application using QNetworkAccessManager to terminate unexpectedly by returning an excessively large Cache-Control header value. This affects only the client side of the connection and does not affect 32-bit builds. The out-of-bounds access is read-only: there is no information disclosure and no code execution, and the impact is limited to a denial of service. 
 
CVSS 4.0 Score: 4.6 / Medium 
 
Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:A/U:Clear 
 
Solution:  Apply the following patch or update to 6.8.9, Qt 6.11.2, or later. 
 

 

 

Blog Topics

Comments

Comments are disabled for this post.

Subscribe to our blog

Try Qt 6.11 Now!

Download the latest release here: www.qt.io/download

Qt 6.11 is now available, with new features and improvements for application developers and device creators.

We're Hiring

Check out all our open positions here and follow us on Instagram to see what it's like to be #QtPeople.