{"id":"CVE-2025-61668","aliases":["GHSA-m8rj-ppph-mj33"],"url":"https://o3.security/vulnerability/CVE-2025-61668","summary":"@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user","details":"Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.","published":"2025-10-02T21:46:32.975Z","modified":"2026-08-12T03:51:30.613626929Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@plone/volto","fixedVersion":"16.34.1"},{"ecosystem":"npm","name":"@plone/volto","fixedVersion":"17.22.2"},{"ecosystem":"npm","name":"@plone/volto","fixedVersion":"18.27.2"},{"ecosystem":"npm","name":"@plone/volto","fixedVersion":"19.0.0-alpha.6"}],"fix":{"url":"https://github.com/plone/volto/commit/58d9f82d2d50ca9a87edbe16fed91762e57c109c","label":"plone/volto@58d9f82"},"references":[{"type":"WEB","url":"http://github.com/plone/volto/releases/tag/18.27.2"},{"type":"WEB","url":"https://github.com/plone/volto/releases/tag/16.34.1"},{"type":"WEB","url":"https://github.com/plone/volto/releases/tag/17.22.2"},{"type":"WEB","url":"https://github.com/plone/volto/releases/tag/19.0.0-alpha.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61668.json"},{"type":"ADVISORY","url":"https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61668"},{"type":"FIX","url":"https://github.com/plone/volto/commit/58d9f82d2d50ca9a87edbe16fed91762e57c109c"},{"type":"FIX","url":"https://github.com/plone/volto/pull/7412"},{"type":"FIX","url":"https://github.com/plone/volto/pull/7413"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.613626929Z"}}