Access Control Vulnerability in Prosody by Prosody Im
CVE-2026-43505

6.5MEDIUM

Key Information:

Vendor

Prosody

Status
Vendor
CVE Published:
1 May 2026

What is CVE-2026-43505?

A significant access control vulnerability exists in Prosody versions prior to 0.12.6 and in 1.0.0 through 13.0.0 before 13.0.5 when mod_proxy65 is enabled. This flaw allows the unauthorized relaying of traffic due to improper handling of access controls, potentially exposing sensitive data and enabling malicious actors to exploit this weakness. Administrators are urged to review their configurations and update to secure versions as part of their cybersecurity maintenance.

Affected Version(s)

Prosody 0 < 0.12.6

Prosody 1.0.0 < 13.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.