---
id: CVE-2025-12385
title: >-
  Allocation of Resources Without Limits or Throttling, Improper Validation of
  Specified Quantity in Input vulnerability in The Qt Company Qt on Windows,
  MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive
  Allocation.



  T…
summary: >-
  Allocation of Resources Without Limits or Throttling, Improper Validation of
  Specified Quantity in Input vulnerability in The Qt Company Qt on Windows,
  MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive
  Allocation.



  T…
severity: none
cwe:
  - CWE-770
  - CWE-1284
published: '2025-12-03'
updated: '2026-07-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12385'
references:
  - url: 'https://codereview.qt-project.org/c/qt/qtdeclarative/+/687239'
    label: a59d8014-47c4-4630-ab43-e1b13cbe58e3
  - url: 'https://codereview.qt-project.org/c/qt/qtdeclarative/+/687766'
    label: a59d8014-47c4-4630-ab43-e1b13cbe58e3
tags:
  - nvd
epss: 0.00315
epssPercentile: 0.21723
ingestedAt: '2026-07-29T10:45:50.494Z'
---

## Overview

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation.


This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive.



This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
