Back to Database
Status published
Critical
CVE-2025-6338
Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
Vulnerability Description
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6338
Credits & Attribution
No credits recorded in the NVD database.
More from The Qt Company
View All →CVE-2025-5992
Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service
Low
2.3
CVE-2025-5991
Use after free in QHttp2ProtocolHandler
Low
2.1
CVE-2025-5683
When loading a specifically crafted ICNS format image file in...
Medium
5.1
CVE-2025-5455
Possible denial of service when passing malformed data in a URL to qDecodeDataUrl
High
8.4
CVE-2025-4211
Improper Link Resolution Before File Access in QFileSystemEngine on Windows
High
7.3
Affected Vendor
The Qt Company
View all reports →Affected Software
Qt
Vulnerable Versions:
0, 5.15.0, 6.8.4, 6.9.0
Timeline
Official Publish:
October 16th, 2025
Last Modified:
October 16th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.