Where
-Infinity
0

redhat/prosodyXEE, Input Validation

Risk 45
Severity
7.5
First published (updated )

Prosody prosodymuc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information…

Risk 43
Severity
7.5
First published (updated )

Fedoraproject FedoraRace Condition

Risk 35
Severity
5.9
First published (updated )

Fedoraproject FedoraProsody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation reque…

Risk 44
Severity
7.8
First published (updated )

Fedoraproject FedoraAn issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option …

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject FedoraAn issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthe…

Risk 43
Severity
7.5
First published (updated )

Fedoraproject FedoraAn issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by defaul…

Risk 27
Severity
5.3
First published (updated )

Debian Debian LinuxThe mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely v…

Risk 86
Severity
9.8
First published (updated )

Prosody prosodyprosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not ve…

Risk 79
Severity
8.8
First published (updated )

debian/prosodyProsody before 0.10.0 allows remote attackers to cause a denial of service (application crash), rela…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Prosody prosodyInput Validation

Risk 27
Severity
5.3
First published (updated )

Prosody prosodyPath Traversal

Risk 35
Severity
5.9
First published (updated )

Prosody prosodyThe mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the sec…

Risk 43
Severity
7.5
First published (updated )

Prosody prosodyProsody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote…

Risk 26
Severity
5
First published (updated )

Prosody prosodyThe json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers…

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Prosody prosodyProsody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column i…

Risk 22
Severity
4.3
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203