Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94116.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94116
Upstream
  • CVE-2026-15037
Published
2026-07-23T13:16:25Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-15037 affecting package qtbase for versions less than 6.6.3-5
Details

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

References

Affected packages

Azure Linux:3 / qtbase

Package

Name
qtbase
Purl
pkg:rpm/azure-linux/qtbase

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.3-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94116.json"