Mellium focuses on SASL and XMPP protocol implementations for messaging and authentication infrastructure, a specialized domain where its vulnerability footprint centers on authentication and certificate validation weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mellium over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48195CRITICAL An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no rando | Dec 31, 2022 | 9.8 | 28 | NO | NO |
CVE-2022-24968MEDIUM In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causi | Feb 11, 2022 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mellium.
Media articles that mention a CVE ID that affects a product developed by Mellium — matched by CVE ID, not by vendor name.