Description
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Published: 2026-06-23
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue exists in the sqlo_natural_join_cond component of OpenLink Virtuoso OpenSource v7.2.11. The flaw allows an attacker to cause a denial of service by sending specially crafted SQL statements to the database. The result is a loss of availability for the database service, which can impact any applications that rely on it. The weakness is identified as resource exhaustion, classified under CWE-770.

Affected Systems

OpenLink Virtuoso OpenSource 7.2.11, specifically the sqlo_natural_join_cond component. No other vendors or product variants are listed. Users deploying this version should verify whether this component is in use in their environment.

Risk and Exploitability

No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating that it has not been widely observed in exploitation. The attack vector is inferred to be the ability to communicate with the database engine and submit malformed SQL, which would typically require either unauthenticated or weakly authenticated access to the database. Because the impact is a service disruption, the risk to affected systems is significant; an attacker who can reach the database interface can potentially interrupt the availability of critical services. The lack of an available patch or workaround in the official CNA data suggests that mitigation will rely on limiting exposure and monitoring for abnormal query activity.

Generated by OpenCVE AI on June 24, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to the database engine to trusted hosts only or enforce strict firewall rules to limit exposure of the database service.
  • Monitor database logs for unusually malformed or large SQL queries that could trigger resource exhaustion, and investigate any suspicious activity.
  • Check the OpenLink Virtuoso project or vendor channels for any updates or patches that address this flaw and apply them as soon as they become available.

Generated by OpenCVE AI on June 24, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted SQL in OpenLink Virtuoso OpenSource v7.2.11
Weaknesses CWE-770

Tue, 23 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted SQL in OpenLink Virtuoso OpenSource v7.2.11
Weaknesses CWE-770

Tue, 23 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-23T16:02:27.477Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61021

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T01:00:06Z

Weaknesses

No weakness.