OpenLink Virtuoso SQL Expression Component Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the SQL expression component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to cause a crash by sending specially crafted SQL statements. The vulnerability can be reproduced using a proof-of-concept that exploits the SQL parser, leading to a stack smashing condition.

Impact

Exploitation of this vulnerability causes the Virtuoso server to crash, disrupting any active database operations or services dependent on the Virtuoso instance.

Reproduction

The vulnerability can be reproduced by first creating a Docker container running OpenLink Virtuoso version 7.2.11. After the server is started, a simple SQL query can be executed to verify that the database is responsive. Once confirmed, the crafted SQL payload that triggers the denial-of-service condition can be executed, causing the server to crash.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.