Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://codereview.qt-project.org/c/qt/qtbase/+/642967 |
|
Tue, 19 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
The Qt Company
The Qt Company qt |
|
| Vendors & Products |
The Qt Company
The Qt Company qt |
Tue, 19 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory. | |
| Title | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TQtC
Published:
Updated: 2026-05-19T14:11:40.774Z
Reserved: 2025-12-12T12:52:17.628Z
Link: CVE-2025-14575
Updated: 2026-05-19T14:11:36.237Z
Status : Awaiting Analysis
Published: 2026-05-19T14:16:27.120
Modified: 2026-06-17T08:36:11.840
Link: CVE-2025-14575
No data.
OpenCVE Enrichment
Updated: 2026-05-19T14:45:07Z