CVE-2025-10729 is a critical use-after-free vulnerability (CWE-416) that occurs when a malformed pattern node is parsed and then deleted, but subsequently accessed, leading to memory corruption. While specific affected products are not detailed, its CVSSv4 score of 9.4 indicates a severe impact. The vulnerability is assessed as having a low attack complexity and no user interaction required, allowing for high confidentiality, integrity, and availability impacts. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting it is not under active widespread exploitation. However, its mention in a BleepingComputer article regarding Microsoft's October 2025 Patch Tuesday and community discussion indicate some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Qt Company | Qt | >= 6.7.0, <= 6.8.4, >= 6.9.0, <= 6.9.2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:H/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.