We found results for “”
CVE-2025-61601
Good to know:
Date: October 9, 2025
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's "Choices" response type. By submitting a malicious payload with a massive array in the "answerIds" field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Check or Handling of Exceptional Conditions
CWE-703Top Fix
Upgrade Version
Upgrade to version https://github.com/bigbluebutton/bigbluebutton.git - v3.0.13
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


