oss-sec mailing list archives
CVE-2025-58047: DoS in Volto (Plone CMS)
From: "Maurits van Rees (Plone)" <maurits () plone org>
Date: Thu, 28 Aug 2025 17:11:02 +0200
A vulnerability has been discovered in Volto, the default NodeJS frontend for the Plone CMS.
### ImpactWhen visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.
### PatchesThe problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:
* Volto 16: [16.34.0](https://github.com/plone/volto/releases/tag/16.34.0) * Volto 17: [17.22.1](https://github.com/plone/volto/releases/tag/17.22.1) * Volto 18: [18.24.0](https://github.com/plone/volto/releases/tag/18.24.0)* Volto 19: [19.0.0-alpha4](https://github.com/plone/volto/releases/tag/19.0.0-alpha.4)
### WorkaroundsMake sure your setup automatically restarts processes that quit with an error. This won't prevent a crash, but it minimises downtime.
### ReportThe problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team (security () plone org).
### Github AdvisoryThe same information was published to GitHub in this [advisory](https://github.com/plone/volto/security/advisories/GHSA-xjhf-7833-3pm5).
Maurits van Rees Plone/Zope Security Team
Current thread:
- CVE-2025-58047: DoS in Volto (Plone CMS) Maurits van Rees (Plone) (Aug 28)
