CVE-2026-43507 Details
Description
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplification from unauthenticated connections.
A denial-of-service vulnerability has been identified in Prosody XMPP server versions prior to 0.12.6 and 13.0.0 through 13.0.0 prior to 13.0.5. This vulnerability allows for memory exhaustion through XML parsing resource amplification, originating from unauthenticated connections. The issue exploits Prosody's per-connection rate limits, which are rendered less effective due to the disproportionate increase in memory usage compared to the volume of data sent by the attacker. Additionally, Prosody does not impose restrictions on the total number of connections, enabling an attacker to escalate the impact by utilizing multiple concurrent connections. The vulnerability also uncovers resource leaks, where a connection continues to deplete server resources even after the stream has ended.
Prosody users are advised to upgrade to version 13.0.5 or 0.12.6. For additional protection, review and adjust system firewall limits to manage the rate and total number of connections from individual IP addresses. This can be done using tools like 'ufw' to limit incoming connection requests on standard XMPP ports.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.unionium.org/ARTICLES/1.HTM | [email protected] | Third Party Advisory |
| https://prosody.im/security/advisory_735dd9d3/ | [email protected] | MitigationPatchVendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/05/01/5 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| prosody prosody | < 0.12.6 >= 13.0.0, < 13.0.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| May 1, 2026 | New CVE Received | [email protected] |