CVE-2025-12385: Improper validation of <img> tag size in Text component parser
Overview
- Severity
- N/A
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2025-Dec
- Released
- 2025-12-06
- Last Updated
- 2026-03-18
- EPSS Score
- 0.16% (percentile: 37.5%)
Affected Products (3)
Open Source Software
- cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0
- azl3 qtdeclarative 6.6.1-1 on Azure Linux 3.0
- cbl2 qt5-qtdeclarative 5.12.5-5 on CBL Mariner 2.0
Revision History
- 2025-12-06: Information published.
- 2025-12-07: Information published.
- 2025-12-08: Information published.
- 2025-12-17: Information published.
- 2026-03-18: Information published.