Skip to main content

Vendor archive

prosody CVEs

Beta · best-effort

22 CVEs tagged to vendor prosody1 Critical, 9 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2026-43507

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplifi…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-43506

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenti…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43505

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activati…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43504

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused sce…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-0217

Published Aug 26, 2022

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37601

Published Jul 30, 2021

muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat roo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10847

Published Jul 30, 2018

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same acr…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18265

Published May 9, 2018

Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0756

Published Jan 29, 2016

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2745

Published Apr 11, 2014

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2744

Published Apr 11, 2014

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows rem…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2532

Published Jun 22, 2011

The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonst…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2531

Published Jun 22, 2011

Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote attackers to cause a denial of servi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2205

Published Jun 22, 2011

Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a craf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1