PatchSiren cyber security CVE debrief
CVE-2025-61025 OpenLink CVE debrief
CVE-2025-61025 is a HIGH-severity vulnerability in openlink virtuoso-opensource v7.2.11, allowing attackers to cause a Denial of Service (DoS) via crafted SQL statements in the sslr_qst_get component. The vulnerability has a CVSS score of 7.5 and was published on 2026-06-23T17:16:39.460Z. The CVE record and NVD detail pages provide further information on this vulnerability. A source reference on GitHub discusses the issue. Users should review their inventory and apply patches or mitigations as necessary.
- Vendor
- OpenLink
- Product
- virtuoso-opensource
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-23
Who should care
Users of openlink virtuoso-opensource v7.2.11 should be aware of this vulnerability and review their inventory for affected systems. Administrators and security teams responsible for openlink virtuoso-opensource installations should prioritize patching or applying mitigations. Developers using this component in their applications should also assess the impact on their projects.
Technical summary
The vulnerability is located in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11. Attackers can exploit this vulnerability by sending crafted SQL statements, potentially leading to a Denial of Service (DoS). The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a high severity. The CWE-89 and CWE-400 weaknesses are associated with this vulnerability.
Defensive priority
Given the high severity and potential for DoS attacks, defenders should prioritize patching or applying mitigations for openlink virtuoso-opensource v7.2.11. Reviewing system inventory and ensuring compensating controls are in place is crucial.
Recommended defensive actions
- Review system inventory for openlink virtuoso-opensource v7.2.11 installations.
- Apply patches or updates provided by the vendor as soon as possible.
- Implement compensating controls, such as monitoring for suspicious SQL activity.
- Restrict access to the affected component, if possible.
- Monitor system performance for signs of potential DoS attacks.
Evidence notes
The CVE record and NVD detail pages provide official information on this vulnerability. A source reference on GitHub discusses the issue. However, details on the exact scope of affected systems and potential mitigations are limited. Further investigation and monitoring are necessary to understand the full impact.
Official resources
-
CVE-2025-61025 CVE record
CVE.org
-
CVE-2025-61025 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
This article is AI-assisted and based on the supplied source corpus.