Products: 3
    Vulnerabilities: 22
    Known Exploited: 0
    1
    Critical Level Threats
    9
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-43507

    Prosody Denial of Service via XML Parsing Resource Amplification

    Last Modified: May 01, 2026
    Published: May 01, 2026

    CVE-2026-43506

    Memory Leak Leads to Denial of Service in Prosody

    Last Modified: May 01, 2026
    Published: May 01, 2026

    CVE-2026-43505

    Unauthorized traffic relay via misconfigured mod_proxy65

    Last Modified: May 01, 2026
    Published: May 01, 2026

    CVE-2026-43504

    Unauthenticated XMPP Traffic Relay via Improper mod_proxy65 Access Control

    Last Modified: May 02, 2026
    Published: May 01, 2026

    CVE-2022-0217

    It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

    Last Modified: Nov 21, 2024
    Published: Aug 26, 2022
    Items Per Page
    Prosody Vulnerabilities & Security CVEs | CVE-DB