Slixmpp Project maintains a focused Python-based XMPP client library whose role in instant-messaging and real-time communication applications places it in the trust boundary of message handling and protocol negotiation. Its observed vulnerabilities center on certificate validation rigor, input-validation robustness, and origin-validation correctness—exposure classes that recur in cryptographic and protocol-parsing libraries where trust establishment is critical to security. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slixmpp Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1000021HIGH slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via | Feb 4, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-5591MEDIUM An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applicat | Feb 9, 2017 | 5.9 | 22 | NO | NO |
CVE-2022-45197HIGH Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp. | Dec 25, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slixmpp Project.
Media articles that mention a CVE ID that affects a product developed by Slixmpp Project — matched by CVE ID, not by vendor name.