CVE-2024-46957: Mellium Xmpp

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

Affected products

  • Mellium Xmpp: from 0.0.1, up to and including 0.21.4

Published 2024-09-25. Last modified 2026-06-17.