CVE-2025-49000

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-service via memory exhaustion. the issue is fixed in versions 0.17.13 and higher. No workaround is available aside from upgrading to the patched version.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*:*

History

17 Dec 2025, 15:10

Type Values Removed Values Added
References () https://github.com/inventree/InvenTree/commit/0826a75ef6dde0ad96d680f52a9cf171ba2ce98b - () https://github.com/inventree/InvenTree/commit/0826a75ef6dde0ad96d680f52a9cf171ba2ce98b - Patch
References () https://github.com/inventree/InvenTree/releases/tag/0.17.13 - () https://github.com/inventree/InvenTree/releases/tag/0.17.13 - Release Notes
References () https://github.com/inventree/InvenTree/security/advisories/GHSA-m2ch-h84r-p9r6 - () https://github.com/inventree/InvenTree/security/advisories/GHSA-m2ch-h84r-p9r6 - Vendor Advisory
CPE cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*:*
First Time Inventree Project
Inventree Project inventree

04 Jun 2025, 14:54

Type Values Removed Values Added
Summary
  • (es) InvenTree es un sistema de gestión de inventario de código abierto. Antes de la versión 0.17.13, el campo de omisión del complemento integrado `label-sheet` no tenía límite superior, por lo que un valor alto obligaba al servidor a asignar una enorme lista de Python. Esto permitía a cualquier usuario autenticado que imprimiera etiquetas activar una denegación de servicio por agotamiento de memoria. El problema se solucionó en las versiones 0.17.13 y posteriores. No hay workaround aparte de actualizar a la versión parcheada.

03 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 21:15

Updated : 2025-12-17 15:10


NVD link : CVE-2025-49000

Mitre link : CVE-2025-49000

CVE.ORG link : CVE-2025-49000


JSON object : View

Products Affected

inventree_project

  • inventree
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling