{"id":"AZL-100947","summary":"CVE-2026-11573 affecting package qtbase 6.6.3-5","details":"Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A document with deeply nested elements parses successfully but exhausts the call stack and terminates the process when serialized. Reachable via QDomDocument::toByteArray() (Qt 4.0 and later), QDomDocument::toString(), QDomDocument::toCString(), QDomNode::save(), and operator\u003c\u003c(QTextStream&, const QDomNode&). Denial of service only — no code execution and no memory disclosure.","modified":"2026-09-14T05:26:59Z","published":"2026-09-08T13:17:17Z","upstream":["CVE-2026-11573"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11573"}],"affected":[{"package":{"name":"qtbase","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/qtbase"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.3-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100947.json"}}],"schema_version":"1.9.0"}