CVE 7.5 HIGH

Volto affected by possible DoS by invoking specific URL by anonymous user_CVE-2025-58047

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-alpha.4. To mitigate downtime, have setup automatically restart processes that quit with an error.

Basic Information

ID CVE-2025-58047
Source GitHub_M
Published Aug 28, 2025 at 17:10

Affected Product

Vendor plone
Product volto
Version < 16.34.0
Affected Versions plone volto < 16.34.0
plone volto >= 17.0.0, < 17.22.1
plone volto >= 18.0.0, < 18.24.0
plone volto >= 19.0.0-alpha.1, < 19.0.0-alpha.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.