CVE-2025-5455
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.
If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort).
This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:M/U:Clear
- Puntuación base: 8.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Requiere interacción del usuario (UI:A) para procesar una URL malformada en QTextDocument/QNetworkReply, causando abort/DoS por assertion. Vector CVSS red sin privilegios con interacción dicta T1203; impacto DoS confirmado por 'denial of service (abort)'.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-5455",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-5455",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-02T12:39:49.722519Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "a59d8014-47c4-4630-ab43-e1b13cbe58e3",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "USER",
"baseScore": 8.4,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:M/U:Clear",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "CLEAR",
"userInteraction": "ACTIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "MODERATE",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "a59d8014-47c4-4630-ab43-e1b13cbe58e3",
"affectedData": [
{
"vendor": "Qt",
"product": "Qt",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "python",
"lessThanOrEqual": "5.15.18"
},
{
"status": "affected",
"version": "6.0.0",
"versionType": "python",
"lessThanOrEqual": "6.5.8"
},
{
"status": "unaffected",
"version": "6.5.9",
"versionType": "python"
},
{
"status": "affected",
"version": "6.6.0",
"versionType": "python",
"lessThanOrEqual": "6.8.3"
},
{
"status": "unaffected",
"version": "6.8.4",
"versionType": "python"
},
{
"status": "affected",
"version": "6.9.0",
"versionType": "python"
},
{
"status": "unaffected",
"version": "6.9.1",
"versionType": "python"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-06-02T09:15:21.493",
"references": [
{
"url": "https://codereview.qt-project.org/c/qt/qtbase/+/642006",
"source": "a59d8014-47c4-4630-ab43-e1b13cbe58e3"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "a59d8014-47c4-4630-ab43-e1b13cbe58e3",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.\n\n\n\nIf the function was called with malformed data, for example, an URL that\ncontained a \"charset\" parameter that lacked a value (such as\n\"data:charset,\"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service\n(abort).\n\n\n\nThis impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1."
},
{
"lang": "es",
"value": "Se encontró un problema en la función privada de la API qDecodeDataUrl() de QtCore, utilizada en QTextDocument y QNetworkReply, y, potencialmente, en el código de usuario. Si la función se llamaba con datos mal formados, por ejemplo, una URL que contenía un parámetro \"charset\" sin valor (como \"data:charset,\"), y Qt se compilaba con aserciones habilitadas, se encontraba con una aserción, lo que resultaba en una denegación de servicio (abortar). Esto afecta a Qt hasta las versiones 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 y 6.9.0. Se ha corregido en las versiones 5.15.19, 6.5.9, 6.8.4 y 6.9.1."
}
],
"lastModified": "2026-07-29T09:16:28.633",
"sourceIdentifier": "a59d8014-47c4-4630-ab43-e1b13cbe58e3"
}