<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:57:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342274</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342274</link>
      <description>EUVD-2026-342274</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342274</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14576</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14576</link>
      <description>&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14576</guid>
    </item>
    <item>
      <title>GHSA-4hpm-v49g-rq7q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4hpm-v49g-rq7q</link>
      <description>&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4hpm-v49g-rq7q</guid>
    </item>
    <item>
      <title>RHSA-2026:20567 — Red Hat Security Advisory: qt6-qtdeclarative security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:20567</link>
      <description>&lt;p&gt;qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:20567</guid>
    </item>
    <item>
      <title>RHSA-2026:24987 — Red Hat Security Advisory: qt6-qtdeclarative security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24987</link>
      <description>&lt;p&gt;qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24987</guid>
    </item>
    <item>
      <title>RLSA-2026:20567 — Important: qt6-qtdeclarative security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:20567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: qt6-qtdeclarative&lt;/p&gt;
&lt;p&gt;Qt6 - QtDeclarative component.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file (CVE-2025-14576)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: qt6-qtdeclarative&lt;/p&gt;
&lt;p&gt;Qt6 - QtDeclarative component.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qt: Qt SVG: Arbitrary QML/JavaScript code injection via malicious SVG file (CVE-2025-14576)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:20567</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-14576</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14576</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: qt6-declarative, Ubuntu:24.04:LTS: qt6-declarative, Ubuntu:25.10: qt6-declarative, Ubuntu:26.04:LTS: qt6-declarative&lt;/p&gt;
&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: qt6-declarative, Ubuntu:24.04:LTS: qt6-declarative, Ubuntu:25.10: qt6-declarative, Ubuntu:26.04:LTS: qt6-declarative&lt;/p&gt;
&lt;p&gt;Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application&amp;#39;s privilege level and data access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14576</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1338 — QT: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1338</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QT ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QT ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1338</guid>
    </item>
  </channel>
</rss>
