CVE-2025-5991 Affecting qtbase-opensource-src package, versions <5.15.8+dfsg-11+deb12u3


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-QTBASEOPENSOURCESRC-18169955
  • published22 Jul 2026
  • disclosed11 Jun 2025

Introduced: 11 Jun 2025

CVE-2025-5991  (opens in a new tab)

How to fix?

Upgrade Echo:latest qtbase-opensource-src to version 5.15.8+dfsg-11+deb12u3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream qtbase-opensource-src package and not the qtbase-opensource-src package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses.

This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.

CVSS Base Scores

version 3.1