Junglewise Threat Intelligence

CVE-2025-61024: OpenLink Virtuoso OpenSource DoS in sqlo_try_in_loop

CVE-2025-61024 · Severity: high · CVSS 7.5 · Published 2026-06-23

Technologies: OpenLink Software Virtuoso OpenSource. Vendors: OpenLink Software.

Executive brief

OpenLink Virtuoso is a high-performance database and middleware platform used for managing large-scale data. A vulnerability in its SQL processing engine allows an attacker to crash the database service by sending specifically formatted database queries. This results in a denial-of-service, potentially disrupting business operations and data availability for applications relying on the database.

Technical details

A Denial of Service (DoS) vulnerability exists in OpenLink Virtuoso OpenSource v7.2.11 within the sqlo_try_in_loop component. The issue is triggered during the compilation or execution of complex, nested SQL statements involving specific combinations of VIEW creation, GROUP BY clauses, and UPDATE operations. An unauthenticated remote attacker with the ability to execute SQL queries can trigger a null pointer dereference or similar memory corruption leading to a service crash (SIGSEGV). The vulnerability was identified via fuzzing and is documented in the project's issue tracker. At the time of reporting, a fix has not been formally confirmed in the advisory text, though a reproduction PoC is available.

Affected products

  • OpenLink Virtuoso OpenSource 7.2.11

Timeline

  • 2024-01-07: disclosed: Issue reported on GitHub with PoC
  • 2026-06-23: advisory: CVE published and NVD record created

References

Related threats