CVE-2025-14575
Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
1th
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.
| CWE | CWE-427 |
| Vendor | qt |
| Product | qt |
| Published | May 19, 2026 |
| Last Updated | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for qt qt
Be the first to know when new unknown vulnerabilities affecting qt qt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Qt / Qt
5.0.0 โค 5.15.19 6.0.0 โค 6.5.9 6.6.0 โค 6.8.3 6.9.0 โค 6.9.1