Junglewise Threat Intelligence

CVE-2025-61019: OpenLink Virtuoso OpenSource DoS in sqlo_key_part_best

CVE-2025-61019 · Severity: info · CVSS 7.5 · Published 2026-06-23

Technologies: OpenLink Software Virtuoso OpenSource. Vendors: OpenLink Software.

Executive brief

OpenLink Virtuoso is a high-performance database and middleware solution. A vulnerability in its SQL processing component allows an attacker to crash the database service by sending specifically crafted SQL queries. This results in a denial-of-service (DoS) condition, potentially disrupting business operations and data availability.

Technical details

A Denial of Service (DoS) vulnerability exists in OpenLink Virtuoso OpenSource v7.2.11 within the sqlo_key_part_best component. The issue is triggered during the query optimization or compilation phase when processing complex SQL statements involving specific combinations of JOINs, subqueries, and ORDER BY clauses. An attacker with the ability to execute SQL queries against the database can cause a segmentation fault (crash) in the server process. The vulnerability was identified via fuzzing and is reproducible using a specific sequence of CREATE TABLE, CREATE VIEW, and SELECT statements. At the time of reporting, the issue was demonstrated in the beta docker image and version 7.2.11.

Affected products

  • OpenLink Virtuoso OpenSource 7.2.11

Timeline

  • 2024-01-07: disclosed: Issue reported on GitHub repository
  • 2026-06-23: advisory: CVE published to NVD

References

Related threats