Critical severity9.8NVD Advisory· Published Sep 25, 2024· Updated Apr 15, 2026
CVE-2024-46957
CVE-2024-46957
Description
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mellium.im/xmppGo | < 0.22.0 | 0.22.0 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.