Prosody is a lightweight, open-source XMPP server implementation that powers instant-messaging and real-time communication infrastructure, often embedded in federated and privacy-oriented deployments where its narrow product footprint belies its role in the messaging ecosystem. Its vulnerability profile concentrates across the server itself and its authentication modules, with recurring weaknesses centered on input validation, authorization logic, resource exhaustion, and race conditions that are characteristic of network service handling. The exposure reflects the parser and state-management demands of protocol-compliant messaging systems, where concurrency and resource control bear directly on denial-of-service resilience and access-control enforcement. Defenders should inventory Prosody instances within their messaging or collaboration infrastructure and treat input-boundary and authentication-logic updates as meaningful; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prosody over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8086CRITICAL The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote ent | Jan 28, 2020 | 9.8 | 30 | NO | NO |
CVE-2026-43507HIGH An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplific | May 1, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-43506HIGH An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthentic | May 1, 2026 | 7.5 | 28 | NO | NO |
CVE-2018-10847HIGH prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same acro | Jul 30, 2018 | 8.8 | 28 | NO | NO |
CVE-2026-43505MEDIUM An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activatio | May 1, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-43504MEDIUM An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scen | May 1, 2026 | 6.5 | 25 | NO | NO |
CVE-2022-0217HIGH It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker inp | Aug 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-37601HIGH muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room | Jul 30, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-32920HIGH Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests. | May 13, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-32919HIGH An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authenticat | May 13, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prosody.
Media articles that mention a CVE ID that affects a product developed by Prosody — matched by CVE ID, not by vendor name.