mellium.im/xmpp
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mellium.im/xmpppage 1 of 1
- CVE-2022-24968MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.21.12022-02-11
In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs becaus…
- CVE-2024-46957CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.22.02024-09-25
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
Check whether mellium.im/xmpp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mellium.im/xmpp CVEs against the assets you own.
Start Free Scan →