CVE-2026-13326 PUBLISHED

Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module

Assigner: Qt
Reserved: 25.06.2026 Published: 11.09.2026 Updated: 11.09.2026

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor qt
Product qt
Versions Default: unaffected
  • affected from 5.2.0 to 6.8.9 (excl.)
  • affected from 6.9.0 to 6.11.2 (excl.)

References

Problem Types

  • CWE-125 Out-of-bounds Read CWE
  • CWE-191 Integer Underflow (Wrap or Wraparound) CWE

Impacts

  • CAPEC-540 Overread Buffers
  • CAPEC-92 Forced Integer Overflow