CVE-2025-58047 Details
Description
Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-alpha.4. To mitigate downtime, have setup automatically restart processes that quit with an error.
A denial-of-service vulnerability has been identified in Volto, a React-based frontend for the Plone Content Management System. This issue affects versions 19.0.0-alpha.1 prior to 19.0.0-alpha.4, 18.0.0 prior to 18.24.0, 17.0.0 prior to 17.22.1, and versions prior to 16.34.0. The vulnerability allows an anonymous user to cause the NodeJS server component of Volto to crash with an error by visiting a specific URL. This issue has been reported by FHNW, a client of Plone provider kitconcept.
Users are advised to upgrade to Volto version 16.34.0, 17.22.1, 18.24.0, or 19.0.0-alpha.4. To minimize downtime, it is recommended to set up automatic restarts for processes that crash with an error.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 28, 2025CISA-ADP
Assessed Aug 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/08/28/3 | CVE | |
| https://github.com/plone/volto/commit/2789a287ac45ad9039fb9161d465ba13241fff0a | [email protected] | Source CodeVendor |
| https://github.com/plone/volto/releases/tag/16.34.0 | [email protected] | Release NotesVendor |
| https://github.com/plone/volto/releases/tag/17.22.1 | [email protected] | Release NotesVendor |
| https://github.com/plone/volto/releases/tag/18.24.0 | [email protected] | Release NotesVendor |
| https://github.com/plone/volto/releases/tag/19.0.0-alpha.4 | [email protected] | Release NotesVendor |
| https://github.com/plone/volto/security/advisories/GHSA-xjhf-7833-3pm5 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| plone volto | < 16.34.0 (semver) >= 17.0.0, < 17.22.1 (semver) >= 18.0.0, < 18.24.0 (semver) >= 19.0.0-alpha.1, < 19.0.0-alpha.4 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Aug 28, 2025 | New CVE Received | [email protected] |
Volerion