{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "fixed": "16.34.0"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "bf1a7ceacf234f222052d5c5a5a210aa3630d187"
            }
          ],
          "repo": "https://github.com/plone/volto",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "17.0.0"
              },
              {
                "fixed": "17.22.1"
              }
            ]
          },
          "events": [
            {
              "introduced": "05da2b2f4703083159332cacddc60715a82c0d51"
            },
            {
              "fixed": "31702f552aa6d9a9d52543d711b634738426e279"
            }
          ],
          "repo": "https://github.com/plone/volto",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "18.0.0"
              },
              {
                "fixed": "18.24.0"
              }
            ]
          },
          "events": [
            {
              "introduced": "92e50ee11c2150485298a95c0498af85f4396f32"
            },
            {
              "fixed": "7591fff2e732febcb404b540956578f991333bd6"
            }
          ],
          "repo": "https://github.com/plone/volto",
          "type": "GIT"
        },
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "19.0.0-alpha.1"
              },
              {
                "fixed": "19.0.0-alpha.4"
              }
            ]
          },
          "events": [
            {
              "introduced": "c207e1ea1336e639fc08fe6525f91bdc1f237b46"
            },
            {
              "fixed": "3214ae4d331b017abc4620b02dfa18ea88ecdd61"
            }
          ],
          "repo": "https://github.com/plone/volto",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-xjhf-7833-3pm5"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-755"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58047.json"
  },
  "details": "Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-alpha.4. To mitigate downtime, have setup automatically restart processes that quit with an error.",
  "id": "CVE-2025-58047",
  "modified": "2026-04-01T23:08:54.015130405Z",
  "published": "2025-08-28T17:10:58.381Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2025/08/28/3"
    },
    {
      "type": "WEB",
      "url": "https://github.com/plone/volto/releases/tag/16.34.0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/plone/volto/releases/tag/17.22.1"
    },
    {
      "type": "WEB",
      "url": "https://github.com/plone/volto/releases/tag/18.24.0"
    },
    {
      "type": "WEB",
      "url": "https://github.com/plone/volto/releases/tag/19.0.0-alpha.4"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58047.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/plone/volto/security/advisories/GHSA-xjhf-7833-3pm5"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58047"
    },
    {
      "type": "FIX",
      "url": "https://github.com/plone/volto/commit/2789a287ac45ad9039fb9161d465ba13241fff0a"
    }
  ],
  "schema_version": "1.7.3",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Volto affected by possible DoS by invoking specific URL by anonymous user"
}