BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.

Project Subscriptions

Vendors Products
Bigbluebutton Subscribe
Bigbluebutton Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 20 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:bigbluebutton:bigbluebutton:*:*:*:*:*:*:*:*

Wed, 15 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Bigbluebutton
Bigbluebutton bigbluebutton
Vendors & Products Bigbluebutton
Bigbluebutton bigbluebutton

Thu, 09 Oct 2025 20:45:00 +0000

Type Values Removed Values Added
Description BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.
Title BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-15T19:47:14.421Z

Reserved: 2025-09-26T16:25:25.151Z

Link: CVE-2025-61601

cve-icon Vulnrichment

Updated: 2025-10-15T19:46:49.905Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-09T21:15:39.477

Modified: 2025-10-20T15:33:21.023

Link: CVE-2025-61601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-10T11:17:33Z

Weaknesses