CVE-2024-46957

CRITICAL

Mellium.im Xmpp < 0.22.0 - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

Scores

CVSS v3 9.8
EPSS 0.0014
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
mellium.im/xmpp 0 - 0.22.0Go
Published Sep 25, 2024
Tracked Since Feb 18, 2026