CVE-2026-13326
Received Received - Intake

Out-of-Bounds Read in Qt NFC Language Parsing

Vulnerability report for CVE-2026-13326, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: TQtC

Description

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
qt qt_nfc *
qt_project qt_connectivity *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read in Qt NFC's language code length parsing. A physically proximate attacker can exploit it by using a crafted NFC tag to cause a denial of service or limited memory disclosure.

Detection Guidance

This vulnerability involves an out-of-bounds read in Qt NFC's language code length parsing via a crafted NFC tag. Detection requires checking for unusual NFC tag interactions or memory access patterns. Monitor system logs for crashes or memory disclosure events after NFC tag scanning. Use tools like 'nfc-list' from libnfc to inspect NFC tags for malformed data.

Impact Analysis

The impact includes potential denial of service, which could disrupt services relying on Qt NFC, and limited memory disclosure, which might expose sensitive data.

Compliance Impact

This vulnerability may impact compliance with GDPR or HIPAA if exploited to disclose limited memory, potentially exposing sensitive data. Denial of service could disrupt systems handling protected health or personal information.

Mitigation Strategies

Update Qt NFC to the latest patched version as soon as possible. Monitor for suspicious NFC tag interactions and restrict physical access to NFC-enabled devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13326. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart