Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation.
This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive.
This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.
CVSS Details
- CVSS 4.0 Base Score: 8.7 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade qt5-qtdeclarativeUpgrade qt5-qtbaseUpgrade qt5-qtdeclarative-examplesUpgrade qt5-qtdeclarative-staticUpgrade qt5-qtbase-staticUpgrade qt5-qtdeclarative-debuginfoUpgrade qt5-qtbase-debuginfoUpgrade qt5-qtbase-commonUpgrade qt5-qtbase-odbcUpgrade qt5-qtdeclarative-develUpgrade qt5-qtbase-mysqlUpgrade qt5-qtbase-private-develUpgrade qt5-qtbase-guiUpgrade qt5-qtbase-examplesUpgrade qt5-qtbase-postgresqlUpgrade qt5-qtbase-devel | May 20, 2026 | May 20, 2026 |
| Ubuntu | — | Upgrade libqt5quick5 (Ubuntu Pro) | Jun 1, 2026 | Dec 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub