PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-61024 OpenLink CVE debrief

CVE-2025-61024 is a HIGH severity vulnerability in openlink virtuoso-opensource v7.2.11 that allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. This issue is located in the sqlo_try_in_loop component. The vulnerability has a CVSS score of 7.5 and was published on 2026-06-23T18:17:40.307Z. The CVE record and NVD detail provide further information about this vulnerability. A source reference is available on GitHub, discussing the issue.

Vendor
OpenLink
Product
virtuoso-opensource
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-23
Original CVE updated
2026-06-23
Advisory published
2026-06-23
Advisory updated
2026-06-23

Who should care

Defenders of openlink virtuoso-opensource v7.2.11 installations should be aware of this HIGH severity Denial of Service (DoS) vulnerability. Attackers can exploit this issue via crafted SQL statements, potentially disrupting service. The vulnerability's CVSS score of 7.5 indicates a significant risk.

Technical summary

The sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 is vulnerable to a Denial of Service (DoS) attack. This is achieved through crafted SQL statements. The vulnerability's CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a Network attack vector with Low attack complexity and No privileges required. The vulnerability is classified under CWE-89.

Defensive priority

Defenders should prioritize patching or mitigating this HIGH severity vulnerability. The vulnerability's impact can be significant, with potential for service disruption.

Recommended defensive actions

  • Review and apply patches or updates for openlink virtuoso-opensource v7.2.11.
  • Implement compensating controls, such as monitoring and filtering of SQL statements.
  • Perform inventory checks to identify affected installations.
  • Consider vendor remediation workflow for openlink virtuoso-opensource v7.2.11.

Evidence notes

The CVE record and NVD detail provide official information about this vulnerability. A source reference on GitHub discusses the issue. However, the corpus does not provide extensive additional metadata or detailed impact analysis.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-61024 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-61024

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-61024 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-61024

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.