#VU119114 Allocation of Resources Without Limits or Throttling in Qt - CVE-2025-12385
Published: December 3, 2025
Qt
Trolltech
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper allocation of resources in Text component parser of the Qt declarative module. A remote attacker can pass overly large values for the width and height in the <img> tag and cause an application to become unresponsive.