pkg:Debian/prosody
31 total CVEsHIGH14MEDIUM11
✅ Check your installed version
All known vulnerabilities
- from 0, < 0.10.2-1
- from 0, < 0.9.7-2+deb8u4
- HIGH7.5CVE-2026-43507An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.from 0
- HIGH7.5CVE-2026-43506An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5.from 0
- from 0, < 0.11.2-1+deb10u3
- from 0, < 0.11.9-2+deb11u1
- HIGH7.5CVE-2021-37601muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and…from 0, < 0.11.9-2
- HIGH7.5CVE-2021-32920Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.from 0, < 0.11.9-1
- from 0, < 0.11.9-1
- from 0, < 0.11.9-1
- from 0, < 0.9.12-2+deb9u1
- from 0, < 0.10.0-1
- from 0, < 0.7.0-1squeeze1+deb6u1
- from 0, < 0.9.9-1
- MEDIUM6.5CVE-2026-43505An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.from 0
- MEDIUM6.5CVE-2026-43504An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled.from 0
- from 0, < 0.11.9-1
- from 0, < 0.9.9-1
- from 0, < 0.8.2-4+deb7u3
- from 0, < 0.9.12-2+deb9u3
- from 0, < 0.11.2-1+deb10u1
- from 0, < 0.11.9-1
- from 0, < 0.8.2-4+deb7u4
- from 0, < 0.9.10-1
- from 0, < 0.7.0-1squeeze1+deb6u2
- —CVE-2014-2745Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial…from 0, < 0.9.4-1
- from 0, < 0.8.2-4+deb7u1
- from 0, < 0.9.4-1
- —CVE-2011-2532The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite…from 0, < 0.8.1-1
- —CVE-2011-2531Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow rem…from 0, < 0.8.1-1
- —CVE-2011-2205Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service…from 0, < 0.7.0-1