CVE-2026-6210
Severity CVSS v4.0:
HIGH
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
06/05/2026
Last modified:
06/05/2026
Description
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image.<br />
<br />
<br />
<br />
When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-marker element (such as a element) that references itself as a marker triggers an out-of-bounds heap read due to the object size difference between QSvgLine and QSvgMarker,<br />
followed by an endless recursion that bypasses the marker recursion <br />
guard through incorrect virtual dispatch. The result is an application <br />
crash (denial of service).<br />
<br />
<br />
<br />
This issue affects Qt SVG: <br />
from 6.7.0 before 6.8.8, from 6.9.0 before 6.11.1.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



