CVE-2025-61601
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.47%
- CWE
- CWE-703
- Published
- 2025-10-09
- Last modified
- 2026-03-12
Affected products
- bigbluebutton bigbluebutton
Weakness type
Related vulnerabilities
- CVE-2026-80135 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-57445 — Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
- CVE-2026-20280 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-82417 — qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- CVE-2026-18638 — Velociraptor server crash via the SetPassword API
- CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
- CVE-2026-16218 — hunvreus devpush Storage Reset Failure storage.py reset_storage improper check or handling of exceptional conditions
- CVE-2026-20187 — Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities