<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 01:23:18 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-13388</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-13388</link>
      <description>cnvd-2022-13388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-13388</guid>
    </item>
    <item>
      <title>EUVD-2026-14303</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-14303</link>
      <description>EUVD-2026-14303</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-14303</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24968</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24968</link>
      <description>&lt;p&gt;In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24968</guid>
    </item>
    <item>
      <title>GHSA-h289-x5wc-xcv8 — Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h289-x5wc-xcv8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: mellium.im/xmpp&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If no TLS configuration is provided by the user, the websocket package constructs its own TLS configuration using recommended defaults. When looking up a WSS endpoint using the DNS TXT record method described in [XEP-0156: Discovering Alternative XMPP Connection Methods](https://xmpp.org/extensions/xep-0156.html) the ServerName field was incorrectly being set to the name of the server returned by the TXT record request, not the name of the initial server we were attempting to connect to. This means that any attacker that can spoof a DNS record (ie. in the absence of DNSSEC, DNS-over-TLS, DNS-over-HTTPS, or similar technologies) could redirect the user to a server of their choosing and as long as it had a valid TLS certificate for itself the connection would succeed, resulting in a MITM situation.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;All users should upgrade to v0.21.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;To work around the issue, manually specify a TLS configuration with the correct hostname.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://mellium.im/cve/cve-2022-24968/
- https://nvd.nist.gov/vuln/detail/CVE-2022-24968&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
* Reach out on XMPP to [sam@samwhited.com](xmpp:sam@samwhited.com?msg)
* Email us at [sam@samwhited.com](mailto:sam@samwhited.com)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: mellium.im/xmpp&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If no TLS configuration is provided by the user, the websocket package constructs its own TLS configuration using recommended defaults. When looking up a WSS endpoint using the DNS TXT record method described in [XEP-0156: Discovering Alternative XMPP Connection Methods](https://xmpp.org/extensions/xep-0156.html) the ServerName field was incorrectly being set to the name of the server returned by the TXT record request, not the name of the initial server we were attempting to connect to. This means that any attacker that can spoof a DNS record (ie. in the absence of DNSSEC, DNS-over-TLS, DNS-over-HTTPS, or similar technologies) could redirect the user to a server of their choosing and as long as it had a valid TLS certificate for itself the connection would succeed, resulting in a MITM situation.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;All users should upgrade to v0.21.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;To work around the issue, manually specify a TLS configuration with the correct hostname.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://mellium.im/cve/cve-2022-24968/
- https://nvd.nist.gov/vuln/detail/CVE-2022-24968&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:
* Reach out on XMPP to [sam@samwhited.com](xmpp:sam@samwhited.com?msg)
* Email us at [sam@samwhited.com](mailto:sam@samwhited.com)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h289-x5wc-xcv8</guid>
    </item>
    <item>
      <title>gsd-2022-24968</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24968</link>
      <description>gsd-2022-24968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24968</guid>
    </item>
  </channel>
</rss>
