Jabberd2 is a niche open-source XMPP server implementation that, despite limited product scope, occupies a prominent position in federated instant-messaging infrastructures where it handles user authentication, message routing, and server-to-server communication. Its vulnerabilities skew toward serious outcomes with a meaningful share reaching critical severity, and recur through permission and authentication weaknesses—including incorrect permission assignment, authentication bypass, sensitive information exposure, and XML entity expansion—that reflect the authentication and protocol-parsing demands of a messaging server. Defenders running Jabberd2 should prioritize patching high-severity disclosures, particularly those affecting authentication and access control; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jabberd2 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10807CRITICAL JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled. | Jul 4, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-18225HIGH The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might | Mar 12, 2018 | 7.8 | 24 | NO | NO |
CVE-2011-1755HIGH jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a cra | Jun 21, 2011 | 7.5 | 24 | NO | NO |
CVE-2012-3525MEDIUM s2s/out.c in jabberd2 2.2.16 and earlier does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) V | Aug 25, 2012 | 5.8 | 21 | NO | NO |
CVE-2017-18226MEDIUM The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveragin | Mar 12, 2018 | 5.5 | 20 | NO | NO |
CVE-2015-2058MEDIUM c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or po | Aug 12, 2015 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jabberd2.
Media articles that mention a CVE ID that affects a product developed by Jabberd2 — matched by CVE ID, not by vendor name.