Skip to main content
EPSS 0.5%top 56%

Qtwebkit opensource src vulnerability (CVE-2026-43658)

0
Medium
Published: 08/21/2026 (08/21/2026, 00:00:00 UTC)
Source: GCVE Database
Product: qtwebkit-opensource-src

Description

UBUNTU-CVE-2026-43658

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Affected versions
0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 00:56:20 UTC

Technical Analysis

CVE-2026-43658 is a vulnerability in WebKitGTK involving improper memory handling that can cause an unexpected process crash when processing maliciously crafted web content. The flaw relates to buffer overflow issues (CWE-119, CWE-120). Exploitation requires user interaction to load malicious content, potentially leading to denial of service and possibly remote code execution, though the latter is not confirmed. Red Hat's advisory highlights that the vulnerability affects packages that use WebKitGTK4, such as GNOME components, and can be exploited locally or via the network in some cases. Mitigations include avoiding untrusted content and removing or updating affected packages. The issue is fixed in updated WebKitGTK packages and Apple OS versions 26.5.

Potential Impact

The vulnerability can cause an unexpected crash of the WebKitGTK process, leading to denial of service. Confidentiality impact is rated high due to potential unauthorized code execution, though this is not confirmed. The flaw could allow attackers to disrupt applications that rely on WebKitGTK to process web content, especially graphical applications in GNOME environments. Remote exploitation requires user interaction except in some GNOME shell cases where local network attackers may exploit it without user interaction.

Mitigation Recommendations

A fix is available in updated versions of WebKitGTK and Apple OS releases 26.5. Users should apply these official patches promptly. Red Hat advises avoiding processing or loading untrusted web content with WebKitGTK. Where feasible, consider removing packages that depend on WebKitGTK4 to reduce exposure, noting that removal may impact GNOME functionality. WebKitGTK3 can be removed without consequence. No additional vendor advisories indicate that no action is required; thus, patching and cautious content handling are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-gc3p-ph3x-xqq6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-43658"]
Database Specific Severity
HIGH
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a83aa87bf8831d539e33f12

Added to database: 08/18/2026, 00:42:47 UTC

Last enriched: 08/18/2026, 00:56:20 UTC

Last updated: 10/01/2026, 21:21:55 UTC

Views: 78

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses