CVE-2025-61668
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-02

Last updated on: 2025-10-06

Assigner: GitHub, Inc.

Description
Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-02
Last Modified
2025-10-06
Generated
2026-05-07
AI Q&A
2025-10-03
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
plone volto 18.0.0
plone volto 17.0.0
plone volto 19.0.0-alpha.1
plone volto 16.34.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the Volto frontend for the Plone CMS. In certain versions, an anonymous user can cause the NodeJS server component of Volto to crash by visiting a specific URL, leading to a denial of service.


How can this vulnerability impact me? :

The vulnerability can cause the Volto NodeJS server to quit unexpectedly, resulting in a denial of service. This can disrupt availability of the affected web application, potentially causing downtime and loss of service for users.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade Volto to one of the fixed versions: 16.34.1, 17.22.2, 18.27.2, or 19.0.0-alpha.6.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart