CVE-2014-2744: Lightwitch Metronome
High severity, CVSS 7.8. EPSS: 3.3% chance of exploitation in the next 30 days.
plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.
Affected products
- Lightwitch Metronome: up to and including 3.4
- Prosody Prosody: up to and including 0.9.3; version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; version 0.4.1 only; …
Published 2014-04-11. Last modified 2026-06-17.