CVE-2025-61601: BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's Choices response type. By submitting a malicious payload with a massive array in the answerIds field, the attacker can cause the current meeting — and potentially all meetings on the server — to become unresponsive. Version 3.0.13 contains a patch. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61601?
CVE-2025-61601 is classified as a high-severity Denial of Service (DoS) vulnerability.
How do I fix CVE-2025-61601?
To fix CVE-2025-61601, upgrade to BigBlueButton version 3.0.13 or later.
Which versions of BigBlueButton are affected by CVE-2025-61601?
CVE-2025-61601 affects all versions of BigBlueButton prior to version 3.0.13.
Can any user exploit CVE-2025-61601?
Yes, any authenticated user can exploit CVE-2025-61601 to freeze or crash the server.
What feature is abused in the CVE-2025-61601 vulnerability?
The polling feature's 'Choices' response type is abused in the CVE-2025-61601 vulnerability.