UAF in XML Parser: <pattern> Node Not Child of Structural Node
CVE-2025-10729 Published on October 3, 2025

Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG
The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.

NVD

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2025-10729 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2025-10729

Want to know whenever a new CVE is published for Qt? stack.watch will email you.

Qt
 

Affected Versions

The Qt Company Qt:

Exploit Probability

EPSS
0.02%
Percentile
6.56%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.