Volto affected by possible DoS by invoking specific URL by anonymous user
Package
Affected versions
< 16.34.0
>= 17.0.0, < 17.22.1
>= 18.0.0, < 18.24.0
>= 19.0.0-alpha.1, < 19.0.0-alpha.4
Patched versions
16.34.0
17.22.1
18.24.0
19.0.0-alpha.4
Description
Published to the GitHub Advisory Database
Aug 28, 2025
Reviewed
Aug 28, 2025
Published by the National Vulnerability Database
Aug 28, 2025
Last updated
Aug 28, 2025
Impact
When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.
Patches
The problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:
Workarounds
Make sure your setup automatically restarts processes that quit with an error. This won't prevent a crash, but it minimises downtime.
Report
The problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team (security@plone.org).
References