CVE-2026-76151: Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

Published Sep 16, 2026
·
Updated

Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via an excessively large Cache-Control header value returned by an untrusted or compromised HTTP server to an application using QNetworkAccessManager. Only the client side of the connection is affected and 32-bit builds are not affected; the out-of-bounds access is read-only, with no information disclosure and no code execution.

Affected Software

1 affected component
Qt Group Qt Framework (QtNetwork module)>=6.0.0<=6.8.8, >=6.9.0<=6.11.1

Event History

Sep 16, 2026
CVE Published
via MITRE·09:58 AM
Data Sourced
via MITRE·09:58 AM
DescriptionWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Affected applications use QNetworkAccessManager in the QtNetwork module on 64-bit builds and receive HTTP responses from an untrusted or compromised server. Only the client side of an HTTP connection is affected; 32-bit builds are not affected.

2

What must an attacker do to trigger the vulnerability?

An attacker needs to control, compromise, or otherwise cause the application to connect to an HTTP server that returns an excessively large Cache-Control response header value. Successful exploitation causes an application crash.

3

Does this issue allow code execution or disclosure of application data?

No. The out-of-bounds access is read-only, and the provided information states that it does not enable information disclosure or code execution.

4

Which Qt versions are affected?

The affected ranges are Qt 6.0.0 through 6.8.8 and Qt 6.9.0 through 6.11.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203