Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Prosody HIGH 7.5
CVE-2026-43506

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b…

Fix: 0.12.6 / 13.0.5+
Fix from $1,950 2026-05-01
Prosody HIGH 7.5
CVE-2026-43507

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b…

Fix: 0.12.6 / 13.0.5+
Fix from $1,950 2026-05-01
Prosody MEDIUM 6.5
CVE-2026-43504

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles …

Fix: 0.12.6 / 13.0.5+
Fix from $1,600 2026-05-01
Prosody MEDIUM 6.5
CVE-2026-43505

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles …

Fix: 0.12.6 / 13.0.5+
Fix from $1,600 2026-05-01
Prosody HIGH 7.5
CVE-2022-0217

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML da…

Fix: 0.11.12+
Fix from $1,950 2022-08-26
Prosody HIGH 7.5
CVE-2021-37601

muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned ent…

Fix: after 0.11.9
Fix from $1,950 2021-07-30
Prosody HIGH 8.8
CVE-2018-10847

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user…

Fix: 0.9.14+
Fix from $1,950 2018-07-30
Prosody MEDIUM 5.3
CVE-2016-0756

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, w…

Fix: after 0.9.9
Fix from $1,600 2016-01-29
Prosody HIGH 7.8
CVE-2014-2745

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service…

Fix: after 0.9.3
Fix from $1,950 2014-04-11
Prosody MEDIUM 5.0
CVE-2011-2532

The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via…

Patch available
Fix from $1,600 2011-06-22
Prosody MEDIUM 5.0
CVE-2011-2205

Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory a…

Fix: after 0.8.0
Fix from $1,600 2011-06-22