CVE-2026-19395: An empty <img> attribute value in styled text triggers a parser error that halts the device.

Published Oct 5, 2026
·
Updated

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.

Affected Software

1 affected component
Qt Qt for MCUs

Event History

Oct 5, 2026
CVE Published
via MITRE·09:18 AM
Data Sourced
via MITRE·09:18 AM
DescriptionWeakness

Frequently Asked Questions

1

What must an attacker control to trigger the device halt?

An attacker would need to cause a Qt for MCUs Text element using styled text to parse an <img> tag containing an attribute with an empty value. The malformed styled-text content reaches an internal check that rejects empty values.

2

Is the halt caused by the default error-handling behavior?

Yes. The failed internal check reports an error, and the default error handler halts the device.

3

How can I identify potentially affected content?

Review styled-text strings rendered by Text elements for <img> tags whose attributes have empty values. Such tags can cause the parser error and resulting halt.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203