GHSA-mh4x-qpf6-hr3q · Severity: high — A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a...
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-marker element (such as a <line> element) that references itself as a marker triggers an out-of-bounds heap read due to the object size difference between QSvgLine and QSvgMarker, followed by an endless recursion that bypasses the marker recursion guard through incorrect virtual dispatch. The result is an application crash (denial of service). This issue affects Qt SVG: from 6.7.0 before 6.8.8, from 6.9.0 before 6.11.1.
Conclusion & alert: CVE-2026-6210 is rated Moderate Risk (40.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-12 | 0.04% | 0.06% | +0.01% |
| 2 | 2026-05-07 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | a59d8014-47c4-4630-ab43-e1b13cbe58e3 |
GHSA-mh4x-qpf6-hr3q · Severity: high — A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-6210 not yet assigned priority: Debian including 2 source packages (qt6-svg, qtsvg-opensource-src), 9 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 7, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-6210 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2026-6210/ |
ubuntu
|
medium | CVE-2026-6210 medium priority: Ubuntu including 2 source packages (qt6-svg, qtsvg-opensource-src), 13 status rows across 8 suites (bionic, focal, jammy, noble, questing, resolute, upstream, xenial): needs-triage 12, released 1. | https://ubuntu.com/security/CVE-2026-6210 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||