Atheme is a niche infrastructure project centered on a single services framework, but its vulnerabilities skew toward serious outcomes with an elevated share reaching critical severity. The recurring weakness classes—improper access control, authentication failures, memory-safety issues including buffer overflows and resource leaks—reflect the C-based implementation and privileged role typical of services infrastructure. Defenders should monitor this vendor's advisories closely despite its narrow footprint, as critical flaws in core infrastructure can have outsized impact; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atheme over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24976CRITICAL Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response lo | Feb 14, 2022 | 9.1 | 30 | NO | NO |
CVE-2016-4478HIGH Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors r | Jun 13, 2016 | 7.5 | 25 | NO | NO |
CVE-2024-27508HIGH Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c. | Feb 27, 2024 | 7.5 | 20 | NO | NO |
CVE-2017-6384HIGH Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of servi | Mar 2, 2017 | 7.5 | 20 | NO | NO |
CVE-2014-9773HIGH modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keywor | Jun 13, 2016 | 7.5 | 20 | NO | NO |
CVE-2012-1576MEDIUM The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a use | Oct 1, 2012 | 6.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atheme.
Media articles that mention a CVE ID that affects a product developed by Atheme — matched by CVE ID, not by vendor name.