Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.
History

Wed, 03 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.
Title Improper validation of <img> tag size in Text component parser
First Time appeared The Qt Company
The Qt Company qt
Weaknesses CWE-1284
CWE-770
CPEs cpe:2.3:a:the_qt_company:qt:*:*:32_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:64_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:android:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:arm:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:ios:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:linux:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:macos:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:windows:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:x86:*:*:*:*:*
Vendors & Products The Qt Company
The Qt Company qt
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TQtC

Published: 2025-12-03T19:38:53.130Z

Updated: 2025-12-03T21:46:42.476Z

Reserved: 2025-10-28T11:53:25.141Z

Link: CVE-2025-12385

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-03T20:16:24.170

Modified: 2025-12-03T20:16:24.170

Link: CVE-2025-12385

cve-icon Redhat

No data.