CVE-2026-43506 Details
Description
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.
A denial-of-service vulnerability has been identified in Prosody XMPP server versions prior to 13.0.5, as well as in the 0.12 series prior to 0.12.6. This vulnerability allows for memory exhaustion through memory leaks caused by unauthenticated connections. The issue arises because Prosody's per-connection rate limits are ineffective against the amplified memory usage, and there are no limits on the total number of connections, enabling increased impact through multiple concurrent connections. Additionally, the vulnerability exposes resource leaks that persist even after a connection stream has ended.
Users are advised to upgrade to Prosody version 13.0.5 or 0.12.6. Additionally, it is recommended to review and adjust system firewall limits to manage the rate and total number of connections to the server. This can be done using tools like 'ufw' to limit incoming connection requests on standard XMPP ports.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://prosody.im/security/advisory_735dd9d3/ | [email protected] | MitigationPatchVendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/05/01/5 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| prosody prosody | < 0.12.6 >= 13.0.0, < 13.0.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | [email protected] |