We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-49000

InvenTree has uncontrolled memory allocation via built-in label-sheet plugin



Description

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory exhaustion. the issue is fixed in versions 0.17.13 and higher. No workaround is available aside from upgrading to the patched version.

Reserved 2025-05-29 | Published 2025-06-03 | Updated 2025-06-04 | Assigner GitHub_M


LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Problem types

CWE-400: Uncontrolled Resource Consumption

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

< 0.17.13
affected

References

github.com/...enTree/security/advisories/GHSA-m2ch-h84r-p9r6

github.com/...ommit/0826a75ef6dde0ad96d680f52a9cf171ba2ce98b

github.com/inventree/InvenTree/releases/tag/0.17.13

cve.org (CVE-2025-49000)

nvd.nist.gov (CVE-2025-49000)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-49000

Support options

Helpdesk Chat, Email, Knowledgebase