Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
Vulnerability Description
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14575
Credits & Attribution
No credits recorded in the NVD database.
More from The Qt Company
View All →Affected Vendor
The Qt Company
View all reports →