CVE-2026-19395

Summary

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.

Affected Software

VendorProductVersion RangeStatus
qtQt for MCUs2.12.0 < 2.12.3affected

Weaknesses

  • CWE-617: CWE-617 Reachable assertion
  • CWE-230: CWE-230 Improper handling of missing values

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References