CVE-2025-6338
An incomplete cleanup in Qt Network's Schannel support on Windows can cause a denial of service over a long period. The flaw affects Qt versions 5.15.0 through 6.8.3 and 6.9.0 up to 6.9.1. It is not currently known to be exploited in the wild.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Qt Network’s Schannel support on Windows, specifically Qt 5.15.0–6.8.3 and 6.9.0–6.9.1. Developers and users running Qt applications on Windows may be impacted.
Real-world impact
An attacker could trigger the vulnerability to make a Qt application crash or become unresponsive, effectively denying service to legitimate users.
Why this severity
The CVSS score of 9.2 reflects a critical denial‑of‑service risk that requires no authentication, no user interaction, and can be exploited remotely with low effort. The high impact and ease of exploitation drive the score.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Oct 16, 2025 · Oct 16, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.