CVE-2025-10728 is a critical vulnerability affecting an unspecified module that renders SVG files. It allows for a Denial of Service (DoS) attack via a stack overflow when processing SVG files containing recursively rendered <pattern> elements. With a CVSS score of 9.4, this vulnerability is easily exploitable with low attack complexity, requiring no user interaction or privileges, and can lead to complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code or active exploitation, it has garnered significant community and media attention, including a mention in a BleepingComputer article regarding Microsoft's October 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Qt Company | Qt | >= 6.7.0, <= 6.8.4, >= 6.9.0, <= 6.9.2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:H/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.