CVE-2014-2744: Lightwitch Metronome

High severity, CVSS 7.8. EPSS: 3.3% chance of exploitation in the next 30 days.

plugins/mod_compression.lua in (1) Prosody before 0.9.4 and (2) Lightwitch Metronome through 3.4 negotiates stream compression while a session is unauthenticated, which allows remote attackers to cause a denial of service (resource consumption) via compressed XML elements in an XMPP stream, aka an "xmppbomb" attack.

Affected products

  • Lightwitch Metronome: up to and including 3.4
  • Prosody Prosody: up to and including 0.9.3; version 0.1.0 only; version 0.2.0 only; version 0.3.0 only; version 0.4.0 only; version 0.4.1 only; …

Published 2014-04-11. Last modified 2026-06-17.