CVE Vulnerabilities

CVE-2025-61602

Improper Check or Handling of Exceptional Conditions

Published: Oct 09, 2025 | Modified: Oct 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed reactionEmojiId in the GraphQL mutation chatSendMessageReaction. Version 3.0.13 contains a patch. No known workarounds are available.

Weakness

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected Software

Name Vendor Start Version End Version
Bigbluebutton Bigbluebutton * 3.0.13 (excluding)

References