CVE-2026-19395

In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the device.

  • Published Oct 5, 2026
  • CVSS 6.6 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-19395 at the National Vulnerability Database