CVE-2025-61028: OpenLink Virtuoso DoS Vulnerability in time_t_to_dt Component
OpenLink Virtuoso Open Source version 7.2.11 contains a vulnerability in its time_t_to_dt component that allows remote attackers to crash the database server by sending specially crafted SQL statements. No authentication is required to trigger the issue, and successful exploitation results in a denial of service condition affecting database availability.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-770, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-23 / 2026-07-15
NVD description (verbatim)
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2025-61028 is a denial-of-service vulnerability in the time_t_to_dt conversion function within OpenLink Virtuoso Open Source v7.2.11. The flaw stems from improper input validation in SQL statement processing, allowing an unauthenticated network attacker to submit malformed queries that cause the service to become unresponsive. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-89 (SQL Injection), indicating both resource exhaustion and potential SQL injection vectors as attack primitives. With a CVSS 3.1 score of 7.5 (HIGH severity), the attack vector is network-accessible, requires no privileges or user interaction, and causes complete loss of availability.
Business impact
An active exploitation of this vulnerability would render Virtuoso database instances unavailable to legitimate users and applications, causing service disruptions, operational downtime, and potential data access delays. Organizations relying on Virtuoso for critical data storage, reporting, or API backends would experience immediate operational impact. Recovery requires manual intervention to restart affected database services, extending recovery time objectives (RTO) and increasing incident response costs.
Affected systems
OpenLink Virtuoso Open Source version 7.2.11 is confirmed vulnerable. Organizations using this specific version should inventory instances immediately. Verify whether your deployment is on v7.2.11 or a patched version by checking SHOW SYSTEM_INFO output or version information in the Virtuoso control panel. Older and newer versions should be validated against the vendor advisory to determine scope.
Exploitability
Exploitation requires only network connectivity and the ability to submit SQL statements—no authentication or user interaction is required. Any network-accessible Virtuoso instance running the affected version is immediately at risk. Public internet-facing deployments, internal databases with permissive firewall rules, and development environments are all potential targets. The attack is straightforward to execute; attackers need only craft and submit the triggering SQL payload.
Remediation
Upgrade OpenLink Virtuoso Open Source to a patched version released after this vulnerability's disclosure. Verify the specific patch version from the official OpenLink Virtuoso vendor advisory. Until patching is possible, implement network-level access controls to restrict SQL connections to trusted internal networks or known application servers, and monitor for suspicious SQL query patterns that might indicate exploitation attempts.
Patch guidance
Consult the official OpenLink Virtuoso release notes and security advisories to identify the specific patched version addressing CVE-2025-61028. Apply patches during a scheduled maintenance window after thorough testing in a non-production environment. Verify successful remediation by confirming the installed version matches or exceeds the minimum patched release and by re-testing with known crafted SQL inputs in a controlled lab setting.
Detection guidance
Monitor database logs for SQL statements containing unusual time_t_to_dt function calls or malformed temporal data conversions that correlate with service crashes or restarts. Track unexpected database shutdowns or high CPU utilization followed by service unavailability. Network-level detection can flag repeated failed connection attempts or unusual query patterns from untrusted sources. Establish baseline logging for SQL syntax errors and anomalous query structures.
Why prioritize this
This vulnerability merits immediate attention due to its high CVSS score (7.5), unauthenticated network exploitability, and direct impact on service availability. Even though it does not enable data theft or system compromise, the ability for any remote attacker to knock a critical database offline makes it a significant operational risk. Organizations should treat this as a high-priority remediation candidate alongside other availability-impacting flaws.
Risk score, explained
The CVSS 3.1 score of 7.5 reflects a high-severity DoS condition that is trivially exploitable (network vector, no authentication, low complexity) but limited in scope to availability impact. The absence of confidentiality or integrity impact prevents a critical rating, but the ease of exploitation and direct service disruption justify the high classification.
Frequently asked questions
Is authentication required to exploit this vulnerability?
No. The vulnerability can be triggered by any remote attacker with network access to the Virtuoso database port. No user credentials or privileges are necessary.
What versions of Virtuoso are affected?
OpenLink Virtuoso Open Source v7.2.11 is confirmed vulnerable. Refer to the vendor advisory to confirm whether your version is affected and to identify available patched releases.
Can this vulnerability be exploited from the internet?
Yes, if your Virtuoso instance is reachable over the network (whether internet-facing or accessible from an internal network). Network segmentation and firewall rules are critical interim controls.
Does this vulnerability allow an attacker to read or modify data?
No. This is exclusively a denial-of-service vulnerability affecting availability. It does not enable unauthorized data access, modification, or system code execution.
This analysis is based on disclosed vulnerability data current as of the modification date. Patch availability, version numbers, and remediation steps must be verified against official OpenLink Virtuoso vendor advisories and security bulletins. No exploit code or weaponized proof-of-concept is provided. Organizations should conduct their own risk assessment based on network topology, data criticality, and business continuity requirements. SEC.co does not guarantee patch timelines or vendor support; contact OpenLink for authoritative remediation guidance. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk
- CVE-2016-20065HIGHUnauthenticated SQL Injection in Product Catalog 8 WordPress Plugin
- CVE-2016-20068HIGHUnauthenticated SQL Injection in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2016-20069HIGHUnauthenticated SQL Injection in WordPress Booking Calendar Contact Form 1.0.23
- CVE-2016-20071HIGHCritical SQL Injection in WordPress 404 Redirection Manager Plugin v1.0
- CVE-2016-20072HIGHBBS e-Franchise WordPress Plugin SQL Injection – Remote Data Exfiltration Risk
- CVE-2016-20073HIGHSQL Injection in Answer My Question 1.3 WordPress Plugin