CVE-2026-43504: Medium severity Prosody prosody vulnerability
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when modproxy65 is enabled. Because modproxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43504?
CVE-2026-43504 has been assessed with a high severity due to its potential to allow relaying of unauthenticated traffic.
How do I fix CVE-2026-43504?
To fix CVE-2026-43504, update Prosody to version 0.12.6 or any version from 13.0.5 onwards.
What versions of Prosody are affected by CVE-2026-43504?
CVE-2026-43504 affects Prosody versions before 0.12.6 and versions from 1.0.0 to 13.0.0 before 13.0.5.
What is the main issue introduced by CVE-2026-43504?
The main issue introduced by CVE-2026-43504 is the mishandling of access control in mod_proxy65 when it is paused.
Can CVE-2026-43504 result in unauthorized access?
Yes, CVE-2026-43504 can result in unauthorized access by allowing unauthenticated traffic to be relayed.