What is CVE-2026-15037?
CVE-2026-15037 is an XML injection flaw in Qt XML due to improper output neutralization in QDom comment, CDATA, and processing-instruction nodes. It affects Qt versions from 4.0.0 through 6.11, allowing untrusted text to inject arbitrary XML markup because node terminators are not properly escaped.
Azərbaycanca: CVE-2026-15037 Qt XML kitabxanasında QDom şərh, CDATA və təlimat node-larının səhv neytrallaşdırılması zəifliyidir. Bu, etibarsız mətn məlumatlarının XML işarələmə kodu inyeksiyasına səbəb ola bilər. Qt 4.0.0-dan 6.11-ə qədər versiyalar təsirlənir və node sərhəd nişanlarının qaçırılmaması səbəbindən tətbiq daxilində məlumat bütövlüyü pozula bilər.
FAQ2
In which component of Qt was CVE-2026-15037 discovered?
CVE-2026-15037 was discovered in the QDom component of the Qt XML library.
Which Qt versions are affected by this vulnerability?
This XML injection vulnerability affects Qt versions from 4.0.0 through 6.11.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.