CVE-2023-51714 is a critical integer overflow vulnerability in the HTTP2 implementation of Qt, specifically affecting versions before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2, including Debian-based systems. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, its high severity and the widespread use of Qt warrant immediate patching. Community discussion and media coverage are minimal, but the risk remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 5.7, < 5.15.17CPE matchmatch criteria | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.11CPE matchmatch criteria | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.5.4CPE matchmatch criteria | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* | ||
>= 6.6.0, < 6.6.2CPE matchmatch criteria | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Qt vulnerabilities
Mar 5, 2026CVE-2023-51714
Jun 11, 2024qt: incorrect integer overflow check
Dec 24, 2023An issue was discovered in the HTTP2 implementation in Qt before 5.15.17 6.x before 6.2.11 6.3.x through 6.5.x before 6.5.4 and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
Dec 12, 2023