Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24650 Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 26 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:part-db_project:part-db:*:*:*:*:*:*:*:*

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Part-db Project
Part-db Project part-db
Vendors & Products Part-db Project
Part-db Project part-db

Thu, 14 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 23:00:00 +0000

Type Values Removed Values Added
Description Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authenticated user can upload a profile picture with a misleading file extension (e.g., .jpg.txt), resulting in a persistent 500 Internal Server Error when attempting to view or edit that user’s profile. This makes the profile permanently inaccessible via the UI for both users and administrators, constituting a Denial of Service (DoS) within the user management interface. This issue has been patched in version 1.17.3.
Title Part-DB Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar Upload
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-08-14T14:51:03.540Z

Reserved: 2025-08-08T21:55:07.963Z

Link: CVE-2025-55194

cve-icon Vulnrichment

Updated: 2025-08-14T13:41:59.829Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-13T23:15:27.327

Modified: 2025-08-26T19:17:38.583

Link: CVE-2025-55194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-16T21:41:23Z