GeoGebra Classic Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in GeoGebra Classic version 5.0.631.0-d. The issue arises in the input field, where attackers can cause the application to crash by sending excessively large buffer content. By generating a buffer of 800,000 repeated characters and pasting it into the 'Entrada:' input field, the application becomes unresponsive and crashes.

Impact

Exploitation of this vulnerability leads to a crash of the GeoGebra application, causing it to become unresponsive.

Reproduction

To reproduce this vulnerability, open GeoGebra Classic version 5.0.631.0-d on a Windows operating system. Once the application is running, use a Python script to create a text file containing 800,000 repeated characters. After the file is created, copy its contents and paste them into the 'Entrada:' input field. The application will crash shortly after the buffer is pasted.

Added: Jan 21, 2026, 7:04 PM
Updated: Jan 21, 2026, 7:04 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.