๐Ÿ” CVE Alert

CVE-2026-19395

UNKNOWN 0.0

An empty <img> attribute value in styled text triggers a parser error that halts the device.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.

CWE CWE-617 CWE-230
Vendor qt
Product qt for mcus
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for qt qt for mcus

Be the first to know when new unknown vulnerabilities affecting qt qt for mcus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

qt / Qt for MCUs
2.12.0 < 2.12.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wiki.qt.io: https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-19395: