CVE-2026-19395
Received
Received - Intake
Qt for MCUs Text Element Image Tag Empty Attribute Denial of Service
Vulnerability report for CVE-2026-19395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-05
Last updated on: 2026-10-05
Assigner: TQtC
Description
Description
In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-617 | The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary. |
| CWE-230 | The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null. |