HIGH
BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId
Published Oct 9, 2025
7.5
HIGHCVSS 3.1
EPSS 0.39%
Description
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmojiId` in the GraphQL mutation `chatSendMessageReaction`. Version 3.0.13 contains a patch. No known workarounds are available.
Affected products
-
- Version < 3.0.13StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bigbluebutton | Bigbluebutton | n/a |
|
- < 3.0.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/bigbluebutton/bigbluebutton/pull/23651 x_refsource_MISCIssue TrackingPatch
- https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-45j2-m26c-3pcm exploitx_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/bigbluebutton/bigbluebutton/pull/23651 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-45j2-m26c-3pcm | exploitx_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 9, 2025
Updated Oct 10, 2025
Reserved Sep 26, 2025
Link CVE-2025-61602
CISA Vulnrichment
Updated Oct 10, 2025