CVE-2024-46957: Mellium Xmpp
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
Affected products
- Mellium Xmpp: from 0.0.1, up to and including 0.21.4
Published 2024-09-25. Last modified 2026-06-17.