๐Ÿ” CVE Alert

CVE-2025-14575

UNKNOWN 0.0

Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
1th

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.

CWE CWE-427
Vendor qt
Product qt
Published May 19, 2026
Last Updated Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for qt qt

Be the first to know when new unknown vulnerabilities affecting qt qt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Qt / Qt
5.0.0 โ‰ค 5.15.19 6.0.0 โ‰ค 6.5.9 6.6.0 โ‰ค 6.8.3 6.9.0 โ‰ค 6.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codereview.qt-project.org: https://codereview.qt-project.org/c/qt/qtbase/+/642967