Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 17 articles for you...
89

Fedora 42 Prosody 13.0.5 Important DoS Memory Exhaustion Vulnerability 2026

Prosody 13.0.5 Upstream is pleased to announce a new minor release from their stable branch. This is a security release for the Prosody 13.0.x stable series. It fixes multiple security issues, some memory leaks and some smaller bugs and changes which have been implemented since the previous release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1efa008794 2026-05-10 03:21:58.076173+00:00 -------------------------------------------------------------------------------- Name : prosody Product : Fedora 42 Version : 13.0.5 Release : 1.fc42 URL : https://prosody.im/ Summary : Flexible communications server for Jabber/XMPP Description : Prosody is a flexible communications server for Jabber/XMPP written in Lua. It aims to be easy to use, and light on resources. For developers it aims to be easy to extend and give a flexible system on which to rapidly develop added functionality, or prototype new protocols. -------------------------------------------------------------------------------- Update Information: Prosody 13.0.5 Upstream is pleased to announce a new minor release from their stable branch. This is a security release for the Prosody 13.0.x stable series. It fixes multiple security issues, some memory leaks and some smaller bugs and changes which have been implemented since the previous release. Full details about the security vulnerabilities can be found in upstream's security advisory. Upstream encourages all Prosody operators on 13.0.4 or earlier to upgrade to 13.0.5 as soon as possible, or to review the advisory and implement appropriate mitigations. A summary of changes in this release: Security mod_proxy65: Consistently apply authorization checks mod_proxy65: Don\u2019t proxy data until after bytestream activation mod_c2s, mod_s2s: Introduce new pre-authentication stanza size limit Add limit for stanza max child elements mod_c2s: Remove timers immediately on disconnection net.server_epoll: Clean uptimers after disconnection Fixes and improvements net.http.parser: Fix handling of chunked request MUC: Advertise hats feature on room JID moduleapi: Use multitable add/remove instead of set (fixes memory leak) mod_cloud_notify: Fix leaking iq response handlers by using send_iq() Improve federation with servers using only IP addresses prosody: Prevent loading local code when installed system-wide mod_http_file_share: Improve handling of Range requests mod_carbons: Fix some carbons decision-making bugs Minor changes net.resolvers: Fix to avoid SRV lookups for IP addresses prosody: Abort earlier on incompatible Lua version mod_turn_external: hand out credentials for type == turns too mod_s2s: Fully validate stream addressing prosodyctl check features: Warn if http file sharing enabled on both host and component util.prosodyctl: Don\u2019t check for mod_posix being disabled, it\u2019s deprecated util.startup: Improve error message when failing to load config file util.x509: Add support for iPAddress certs prosodyctl: Trim any trailing newline from password entry mod_admin_shell: Make cert index search path relative to config file mod_admin_shell: Improve multi-host command handling mod_admin_shell: Show help listing when specifying only a section name mod_admin_shell: Ensure password validity when setting passwords for new/existing users mod_account_activity: Handle authentication provider returning no user info config: Use default value when enum option has incorrect value mod_http: \u201cHandle\u201d streaming requests to avoid invoking redirect handler -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Robert Scheck 13.0.5-1 - Upgrade to 13.0.5 (#2463898) * Thu Apr 16 2026 Tom Callaway - 13.0.4-3 - rebuild * Sun Mar 15 2026 Tom Callaway - 13.0.4-2 - rebuild for lua 5.5 - apply upstream fix for configure - make a new patch to actually support lua 5.5 -------------------------------------------------------------------------------- References: [ 1] Bug #2464363 - CVE-2026-43507 Prosody: Prosody: Denial of Service via XML parsing resource amplification https://bugzilla.redhat.com/show_bug.cgi?id=2464363 [ 2 ] Bug #2464412 - CVE-2026-43504 Prosody: mod_proxy65: Prosody: Unauthenticated traffic relay due to access control mishandling in mod_proxy65 https://bugzilla.redhat.com/show_bug.cgi?id=2464412 [ 3 ] Bug #2464452 - CVE-2026-43505 Prosody: mod_proxy65: Prosody: Unauthorized traffic relay via mod_proxy65 access control flaw https://bugzilla.redhat.com/show_bug.cgi?id=2464452 [ 4 ] Bug #2464492 - CVE-2026-43506 Prosody: Prosody: Denial of Service via memory exhaustion from unauthenticated connections https://bugzilla.redhat.com/show_bug.cgi?id=2464492 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1efa008794' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Prosody's new version addresses critical issues including memory exhaustion and unauthorized access. Immediate upgrade recommended.. Fedora security updates, Prosody 13.0.5, Denial of Service fix, memory exhaustion vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 10, 2026 Important Fedora
89

Fedora 43 Prosody 13.0.5 Critical Security Advisory 2026-36c53b9ca8

Prosody 13.0.5 Upstream is pleased to announce a new minor release from their stable branch. This is a security release for the Prosody 13.0.x stable series. It fixes multiple security issues, some memory leaks and some smaller bugs and changes which have been implemented since the previous release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-36c53b9ca8 2026-05-10 03:04:49.565358+00:00 -------------------------------------------------------------------------------- Name : prosody Product : Fedora 43 Version : 13.0.5 Release : 1.fc43 URL : https://prosody.im/ Summary : Flexible communications server for Jabber/XMPP Description : Prosody is a flexible communications server for Jabber/XMPP written in Lua. It aims to be easy to use, and light on resources. For developers it aims to be easy to extend and give a flexible system on which to rapidly develop added functionality, or prototype new protocols. -------------------------------------------------------------------------------- Update Information: Prosody 13.0.5 Upstream is pleased to announce a new minor release from their stable branch. This is a security release for the Prosody 13.0.x stable series. It fixes multiple security issues, some memory leaks and some smaller bugs and changes which have been implemented since the previous release. Full details about the security vulnerabilities can be found in upstream's security advisory. Upstream encourages all Prosody operators on 13.0.4 or earlier to upgrade to 13.0.5 as soon as possible, or to review the advisory and implement appropriate mitigations. A summary of changes in this release: Security mod_proxy65: Consistently apply authorization checks mod_proxy65: Don\u2019t proxy data until after bytestream activation mod_c2s, mod_s2s: Introduce new pre-authentication stanza size limit Add limit for stanza max child elements mod_c2s: Remove timers immediately on disconnection net.server_epoll: Clean uptimers after disconnection Fixes and improvements net.http.parser: Fix handling of chunked request MUC: Advertise hats feature on room JID moduleapi: Use multitable add/remove instead of set (fixes memory leak) mod_cloud_notify: Fix leaking iq response handlers by using send_iq() Improve federation with servers using only IP addresses prosody: Prevent loading local code when installed system-wide mod_http_file_share: Improve handling of Range requests mod_carbons: Fix some carbons decision-making bugs Minor changes net.resolvers: Fix to avoid SRV lookups for IP addresses prosody: Abort earlier on incompatible Lua version mod_turn_external: hand out credentials for type == turns too mod_s2s: Fully validate stream addressing prosodyctl check features: Warn if http file sharing enabled on both host and component util.prosodyctl: Don\u2019t check for mod_posix being disabled, it\u2019s deprecated util.startup: Improve error message when failing to load config file util.x509: Add support for iPAddress certs prosodyctl: Trim any trailing newline from password entry mod_admin_shell: Make cert index search path relative to config file mod_admin_shell: Improve multi-host command handling mod_admin_shell: Show help listing when specifying only a section name mod_admin_shell: Ensure password validity when setting passwords for new/existing users mod_account_activity: Handle authentication provider returning no user info config: Use default value when enum option has incorrect value mod_http: \u201cHandle\u201d streaming requests to avoid invoking redirect handler -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Robert Scheck 13.0.5-1 - Upgrade to 13.0.5 (#2463898) * Thu Apr 16 2026 Tom Callaway - 13.0.4-3 - rebuild * Sun Mar 15 2026 Tom Callaway - 13.0.4-2 - rebuild for lua 5.5 - apply upstream fix for configure - make a new patch to actually support lua 5.5 -------------------------------------------------------------------------------- References: [ 1] Bug #2464363 - CVE-2026-43507 Prosody: Prosody: Denial of Service via XML parsing resource amplification https://bugzilla.redhat.com/show_bug.cgi?id=2464363 [ 2 ] Bug #2464412 - CVE-2026-43504 Prosody: mod_proxy65: Prosody: Unauthenticated traffic relay due to access control mishandling in mod_proxy65 https://bugzilla.redhat.com/show_bug.cgi?id=2464412 [ 3 ] Bug #2464452 - CVE-2026-43505 Prosody: mod_proxy65: Prosody: Unauthorized traffic relay via mod_proxy65 access control flaw https://bugzilla.redhat.com/show_bug.cgi?id=2464452 [ 4 ] Bug #2464492 - CVE-2026-43506 Prosody: Prosody: Denial of Service via memory exhaustion from unauthenticated connections https://bugzilla.redhat.com/show_bug.cgi?id=2464492 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-36c53b9ca8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Discover critical security advisory for Prosody 13.0.5 on Fedora 43 addressing multiple vulnerabilities and upgrade options.. Fedora Prosody 13.0.5 update critical security issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 10, 2026 Critical Fedora
87

Debian 11 Prosody Important Denial Of Service Sec Issues DSA-6252-1

Multiple security issues were found in Prosody, a lightweight Jabber/XMPP server, which could result in denial of service or insufficient access control when using the SOCKS5 proxy module. For the oldstable distribution (bookworm), these problems have been fixed in version 0.12.3-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6252-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 07, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : prosody CVE ID : CVE-2026-43504 CVE-2026-43505 CVE-2026-43506 CVE-2026-43507 Multiple security issues were found in Prosody, a lightweight Jabber/XMPP server, which could result in denial of service or insufficient access control when using the SOCKS5 proxy module. For the oldstable distribution (bookworm), these problems have been fixed in version 0.12.3-1+deb12u1. For the stable distribution (trixie), these problems have been fixed in version 13.0.1-1+deb131u. We recommend that you upgrade your prosody packages. For the detailed security status of prosody please refer to its security tracker page at: https://security-tracker.debian.org/tracker/prosody Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple security issues in Prosody could lead to denial of service and insufficient access control. Update recommended.. Prosody Security Issue, Debian Advisory, Denial of Service, Access Control. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2026 Important Debian
87

Debian DSA-5047-2: Critical Prosody Memory Leak Resolved

The update for prosody released as DSA 5047 introduced a memory leak. Updated prosody packages are now available to correct this issue. For the oldstable distribution (buster), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5047-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 29, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : prosody Debian Bug : 1004173 The update for prosody released as DSA 5047 introduced a memory leak. Updated prosody packages are now available to correct this issue. For the oldstable distribution (buster), this problem has been fixed in version 0.11.2-1+deb10u4. For the stable distribution (bullseye), this problem has been fixed in version 0.11.9-2+deb11u2. We recommend that you upgrade your prosody packages. For the detailed security status of prosody please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/prosody Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolved prosody memory optimization issue in Debian DSA-5050-1 security patch for legacy and current distributions.. prosody memory leak, Debian update, security advisory, Debian DSA-5047-2, prosody fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 29, 2022 Critical Debian
87

Debian: DSA-5047-1 Moderate: Prosody Denial Of Service Issue

Matthew Wild discovered that the WebSockets code in Prosody, a lightweight Jabber/XMPP server, was susceptible to denial of service. For the oldstable distribution (buster), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5047-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 15, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : prosody CVE ID : CVE-2022-0217 Matthew Wild discovered that the WebSockets code in Prosody, a lightweight Jabber/XMPP server, was susceptible to denial of service. For the oldstable distribution (buster), this problem has been fixed in version 0.11.2-1+deb10u3. For the stable distribution (bullseye), this problem has been fixed in version 0.11.9-2+deb11u1. We recommend that you upgrade your prosody packages. For the detailed security status of prosody please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/prosody Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A security vulnerability was discovered by Martin Green in the WebSocket implementation of Prosody, which has now been addressed in the latest Debian patches.. WebSockets Update, DoS Security, Prosody Server, Debian Advisory, Security Fix. . LinuxSecurity.com Team

Calendar%202 Jan 15, 2022 Debian
202

openSUSE: 2022:0012-1 Important: Prosody XML Doctype Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for prosody ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0012-1 Rating: important References: #1194596 Cross-References: CVE-2022-0217 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for prosody fixes the following issues: Update to 0.11.12: * CVE-2022-0217: util.xml: Do not allow doctypes, comments or processing instructions (bsc#1194596) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-12=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): prosody-0.11.12-bp153.2.12.1 References: https://www.suse.com/security/cve/CVE-2022-0217.html https://bugzilla.suse.com/1194596 . This Ubuntu Security Patch reveals critical enhancements for prosody impacting Backports SLE-15-SP3.. openSUSE Prosody Update, XML Doctype Fix, Security Update for Prosody. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 14, 2022 Important OpenSUSE
202

openSUSE: 2021:1185-2 low: Prosody Configuration Issue Resolution

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for prosody ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1173-1 Rating: moderate References: #1188976 Cross-References: CVE-2021-37601 CVSS scores: CVE-2021-37601 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for prosody fixes the following issues: prosody was updated to 0.11.10: Security: * MUC: Fix logic for access to affiliation lists CVE-2021-37601 (boo#1188976) https://prosody.im/security/advisory_20210722/ Minor changes: * prosodyctl: Add ???limits??? to known globals to warn about misplacing it * util.ip: Fix netmask for link-local address range * mod_pep: Remove obsolete node restoration code * util.pubsub: Fix traceback if node data not initialized Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1173=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64): prosody-0.11.10-bp153.2.6.2 References: https://www.suse.com/security/cve/CVE-2021-37601.html https://bugzilla.suse.com/1188976 . A new security patch for Prosody has been released for openSUSE, targeting the vulnerability identified as CVE-2021-37601, categorized with moderate threat level.. openSUSE Security Update, prosody Patch, Access Control Issue. . LinuxSecurity.com Team

Calendar%202 Aug 20, 2021 OpenSUSE
198

Arch Linux: ASA-202108-11 Medium: Prosody Information Disclosure

The package prosody before version 1:0.11.10-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202108-11 ========================================= Severity: Medium Date : 2021-08-10 CVE-ID : CVE-2021-37601 Package : prosody Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-2237 Summary ====== The package prosody before version 1:0.11.10-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 1:0.11.10-1. # pacman -Syu "prosody> =1:0.11.10-1" The problem has been fixed upstream in version 0.11.10. Workaround ========= None. Description ========== It was discovered that Prosody 0.11.0 up to 0.11.9 exposes the list of entities (Jabber/XMPP addresses) affiliated (part of) a Multi-User chat to any user, even if they are currently not part of the chat or if their affiliation would not let them become part of the chat, if the whois room configuration was set to anyone. This allows any entity to access the list of admins, members, owners and banned entities of any federated XMPP group chat of which they know the address if it is hosted on a vulnerable Prosody server. Impact ===== A remote attacker could disclose the list of admins, members, ownersand banned entities of any federated XMPP group chat of which they know the address. References ========= https://bugs.archlinux.org/task/71641 https://prosody.im/security/advisory_20210722/ https://prosody.im/security/advisory_20210722/1.patch http://hg.prosody.im/_challenge?redirect_uri=/0.11/rev/d117b92fd8e4 https://security.archlinux.org/CVE-2021-37601 . Arch Linux Security Advisory ASA-202108-11 addresses medium severity information disclosure in Prosody.. Arch Linux, Prosody, Information Disclosure, Security Advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Aug 13, 2021 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200