PT-2025-41489 · Unknown · Bigbluebutton

·

CVE-2025-61601

·

Published

2025-10-09

·

Updated

2025-10-20

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BigBlueButton versions prior to 3.0.13
Description BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) issue exists that allows any authenticated user to freeze or crash the server by abusing the polling feature's Choices response type. An attacker can submit a malicious payload with a massive array in the answerIds field, causing the current meeting – and potentially all meetings on the server – to become unresponsive. The attack leverages the answerIds field to overwhelm the server's processing capabilities.
Recommendations Update to version 3.0.13 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61601
GHSA-73J3-V3FQ-FQX5

Affected Products

Bigbluebutton