CVE-2025-61601 Details
Description
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.
A denial-of-service vulnerability has been identified in BigBlueButton versions prior to 3.0.13. This issue allows any authenticated user to freeze or crash the entire server by exploiting the polling feature's 'Choices' response type. The vulnerability arises from the server's failure to properly validate the size of the 'answerIds' array in the 'pollSubmitUserVote' GraphQL mutation. By submitting a malicious payload with a massive array, an attacker can disrupt the current meeting and potentially all meetings on the server, causing them to become unresponsive. Version 3.0.13 includes a patch for this vulnerability, and no known workarounds are available.
Users are advised to upgrade to BigBlueButton version 3.0.13, which includes the necessary patch. Instructions for updating can be found in the BigBlueButton documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-73j3-v3fq-fqx5 | CISA-ADP | ExploitVendor Advisory |
| https://www.youtube.com/watch?v=BwROSVIYjOY | CISA-ADP | Exploit |
| https://github.com/bigbluebutton/bigbluebutton/pull/23662 | [email protected] | Issue TrackingPatch |
| https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-73j3-v3fq-fqx5 | [email protected] | ExploitVendor Advisory |
| https://www.youtube.com/watch?v=BwROSVIYjOY | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-703 | Improper Check or Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bigbluebutton bigbluebutton | < 3.0.13 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | Initial Analysis | [email protected] |
| Oct 15, 2025 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | New CVE Received | [email protected] |