Vulnerabilities/

Volto affected by possible DoS by invoking specific URL by anonymous user

Severity:
High

Description

When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.

Recommendation

Update the @plone/volto package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@plone/volto
Anything's wrong? Let us know Last updated on August 28, 2025

This issue is available in SmartScanner Professional

See Pricing