CVE-2026-43507: High severity Prosody prosody vulnerability
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplification from unauthenticated connections.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43507?
CVE-2026-43507 has a high severity due to its potential to cause Denial of Service through memory exhaustion.
How do I fix CVE-2026-43507?
To fix CVE-2026-43507, upgrade Prosody to version 0.12.6 or any of the versions between 1.0.0 and 13.0.5 inclusive.
What types of systems are affected by CVE-2026-43507?
CVE-2026-43507 affects Prosody versions before 0.12.6 and between 1.0.0 and 13.0.0 before 13.0.5.
Can CVE-2026-43507 be exploited remotely?
Yes, CVE-2026-43507 can be exploited via unauthenticated remote connections that lead to memory exhaustion.
What are the implications of CVE-2026-43507 for users?
Users of affected Prosody versions may experience service disruptions due to Denial of Service caused by XML parsing resource amplification.