CVE Feed

    Dashboard / CVE / CVE-2025-49000

    CVE-2025-49000

    InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory exhaustion. the issue is fixed in versions 0.17.13 and higher. No workaround is available aside from upgrading to the patched version.

    Published:Jun 3, 2025
    Last Modified:Dec 17, 2025
    EPS:Jun 3, 2025
    EPSS Score:0.00033
    CVSS Score:3.5

    Affected Products

    Vendor
    Inventree
    Product
    Inventree
    Vendor
    Inventree Project
    Product
    Inventree

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High