Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16786 | InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory exhaustion. the issue is fixed in versions 0.17.13 and higher. No workaround is available aside from upgrading to the patched version. |
Wed, 17 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inventree Project
Inventree Project inventree |
|
| CPEs | cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Inventree Project
Inventree Project inventree |
Wed, 04 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Jun 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory exhaustion. the issue is fixed in versions 0.17.13 and higher. No workaround is available aside from upgrading to the patched version. | |
| Title | InvenTree has uncontrolled memory allocation via built-in label-sheet plugin | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-04T13:49:33.402Z
Reserved: 2025-05-29T16:34:07.174Z
Link: CVE-2025-49000
Updated: 2025-06-04T13:49:28.445Z
Status : Analyzed
Published: 2025-06-03T21:15:22.250
Modified: 2025-12-17T15:10:49.213
Link: CVE-2025-49000
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:17Z
EUVD