CVE-2024-39936

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/07/2024
Last modified:
29/11/2025

Description

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* 5.15.18 (excluding)
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* 6.0.0 (including) 6.2.13 (excluding)
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* 6.3.0 (including) 6.5.7 (excluding)
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* 6.6.0 (including) 6.7.3 (excluding)