CVE-2026-43504

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.
References
Link Resource
https://prosody.im/security/advisory_735dd9d3/ Mitigation Patch Vendor Advisory
https://www.openwall.com/lists/oss-security/2026/05/01/5 Mailing List Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

History

01 May 2026, 17:15

Type Values Removed Values Added
First Time Prosody
Prosody prosody
CPE cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*
References () https://prosody.im/security/advisory_735dd9d3/ - () https://prosody.im/security/advisory_735dd9d3/ - Mitigation, Patch, Vendor Advisory
References () https://www.openwall.com/lists/oss-security/2026/05/01/5 - () https://www.openwall.com/lists/oss-security/2026/05/01/5 - Mailing List, Patch, Third Party Advisory

01 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 15:16

Updated : 2026-05-01 17:15


NVD link : CVE-2026-43504

Mitre link : CVE-2026-43504

CVE.ORG link : CVE-2026-43504


JSON object : View

Products Affected

prosody

  • prosody
CWE
CWE-863

Incorrect Authorization