Executive brief
Plone Volto is a headless CMS frontend framework built on Node.js that serves web content. An unauthenticated attacker can crash the Volto Node.js server by accessing a specific URL, causing service unavailability. While patches are available for all supported versions, unpatched instances are susceptible to repeated crashes that disrupt service availability.
Technical details
The vulnerability is a null pointer dereference (CWE-476) in the Volto Node.js server that can be triggered by accessing a specific URL without authentication. An anonymous user can cause the server process to quit with an error by invoking this URL, resulting in denial of service. The attack requires no privileges, authentication, or user interaction—only network reachability to the Volto server. Patches have been released and backported to versions 16.34.1, 17.22.2, 18.27.2, and 19.0.0-alpha.6. Affected installations should upgrade immediately; a temporary workaround is to configure automatic process restart to minimize downtime.
Affected products
- Plone Volto <16.34.1, 17.0.0 to <17.22.2, 18.0.0 to <18.27.2, 19.0.0-alpha.1 to <19.0.0-alpha.6
Timeline
- 2025-10-01: disclosed: GHSA-m8rj-ppph-mj33 published
- 2025-10-01: patched: Patches released for versions 16.34.1, 17.22.2, 18.27.2, 19.0.0-alpha.6