ThreatCluster

Multiple CVEs Identified in Qt HTTP2 Implementation

First seen 18 Feb 2026, 16:24 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been discovered in the HTTP2 implementation of Qt affecting multiple versions. CVE-2023-51714, published on December 24, 2023, involves an HPack integer overflow check issue, while CVE-2024-39936, published on July 4, 2024, relates to premature execution of security decisions due to signal processing delays. Both vulnerabilities could impact applications relying on affected Qt versions.

Timeline

2023-12-24
CVE-2023-51714 published
2024-07-04
CVE-2024-39936 published
2026-02-18
Articles published detailing both CVEs