CVE-2026-43506

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.
References
Link Resource
https://prosody.im/security/advisory_735dd9d3/ Mitigation Patch Vendor Advisory
https://www.openwall.com/lists/oss-security/2026/05/01/5 Mailing List Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*
cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

History

01 May 2026, 17:09

Type Values Removed Values Added
References () https://prosody.im/security/advisory_735dd9d3/ - () https://prosody.im/security/advisory_735dd9d3/ - Mitigation, Patch, Vendor Advisory
References () https://www.openwall.com/lists/oss-security/2026/05/01/5 - () https://www.openwall.com/lists/oss-security/2026/05/01/5 - Mailing List, Patch, Third Party Advisory
First Time Prosody
Prosody prosody
CPE cpe:2.3:a:prosody:prosody:*:*:*:*:*:*:*:*

01 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 15:16

Updated : 2026-05-01 17:09


NVD link : CVE-2026-43506

Mitre link : CVE-2026-43506

CVE.ORG link : CVE-2026-43506


JSON object : View

Products Affected

prosody

  • prosody
CWE
CWE-401

Missing Release of Memory after Effective Lifetime