๐Ÿ” CVE Alert

CVE-2025-12385

UNKNOWN 0.0

Improper validation of <img> tag size in Text component parser

CVSS Score
0.0
EPSS Score
0.3%
EPSS Percentile
20th

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

CWE CWE-770 CWE-1284
Vendor qt
Product qt
Published Dec 3, 2025
Last Updated Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for qt qt

Be the first to know when new unknown vulnerabilities affecting qt qt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Qt / Qt
5.0.0 โ‰ค 6.5.10 6.6.0 โ‰ค 6.8.5 6.9.0 โ‰ค 6.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codereview.qt-project.org: https://codereview.qt-project.org/c/qt/qtdeclarative/+/687239 codereview.qt-project.org: https://codereview.qt-project.org/c/qt/qtdeclarative/+/687766