PatchSiren cyber security CVE debrief
CVE-2025-61024 OpenLink CVE debrief
CVE-2025-61024 is a HIGH severity vulnerability in openlink virtuoso-opensource v7.2.11 that allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. This issue is located in the sqlo_try_in_loop component. The vulnerability has a CVSS score of 7.5 and was published on 2026-06-23T18:17:40.307Z. The CVE record and NVD detail provide further information about this vulnerability. A source reference is available on GitHub, discussing the issue.
- Vendor
- OpenLink
- Product
- virtuoso-opensource
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-23
Who should care
Defenders of openlink virtuoso-opensource v7.2.11 installations should be aware of this HIGH severity Denial of Service (DoS) vulnerability. Attackers can exploit this issue via crafted SQL statements, potentially disrupting service. The vulnerability's CVSS score of 7.5 indicates a significant risk.
Technical summary
The sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 is vulnerable to a Denial of Service (DoS) attack. This is achieved through crafted SQL statements. The vulnerability's CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a Network attack vector with Low attack complexity and No privileges required. The vulnerability is classified under CWE-89.
Defensive priority
Defenders should prioritize patching or mitigating this HIGH severity vulnerability. The vulnerability's impact can be significant, with potential for service disruption.
Recommended defensive actions
- Review and apply patches or updates for openlink virtuoso-opensource v7.2.11.
- Implement compensating controls, such as monitoring and filtering of SQL statements.
- Perform inventory checks to identify affected installations.
- Consider vendor remediation workflow for openlink virtuoso-opensource v7.2.11.
Evidence notes
The CVE record and NVD detail provide official information about this vulnerability. A source reference on GitHub discusses the issue. However, the corpus does not provide extensive additional metadata or detailed impact analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-61024 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-61024
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-61024 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-61024
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openlink/virtuoso-opensource/issues/1227
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.