Junglewise Threat Intelligence

CVE-2025-61025: OpenLink Virtuoso OpenSource Denial of Service in sslr_qst_get

CVE-2025-61025 · Severity: info · CVSS 5.3 · Published 2026-06-23

Technologies: OpenLink Software Virtuoso OpenSource. Vendors: OpenLink Software.

Executive brief

OpenLink Virtuoso OpenSource is a high-performance database engine used for managing large-scale data and web applications. A vulnerability in the way it processes specific database queries allows an attacker to crash the service, leading to a denial-of-service. This could disrupt business operations and prevent users from accessing data stored in the database.

Technical details

A Denial of Service (DoS) vulnerability exists in the sslr_qst_get component of OpenLink Virtuoso OpenSource v7.2.11. The issue is triggered during the execution of complex, nested SQL statements involving CHECK constraints, subqueries, and specific function calls, which leads to a process crash (segmentation fault). An attacker with the ability to execute SQL queries against the database can exploit this to disrupt service availability. The vulnerability was identified via fuzzing and is documented in the project's issue tracker. No official patch is confirmed in the provided text, though it has been reported to the maintainers.

Affected products

  • OpenLink Virtuoso OpenSource 7.2.11

Timeline

  • 2024-01-07: disclosed: Issue reported on GitHub with PoC
  • 2026-06-23: advisory: CVE published by NVD

References

Related threats