Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-39936


An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..


Published

2024-07-04T21:15:10.180

Last Modified

2025-03-19T20:15:18.770

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qt qt < 5.15.18 Yes
Application qt qt < 6.2.13 Yes
Application qt qt < 6.5.7 Yes
Application qt qt < 6.7.3 Yes

References