02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: redhatIt was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 5.37% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 92.1% of scored records. A rank, not a probability.
- NVD base score
- 7.5 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2022-08-26 17:25Z4 YR AGO
- Last updated
- 2024-08-02 23:18Z2 YR AGO
- Reserved
- 2022-01-13
- Assigning CNA
- redhat
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')Base
- CWE-611Improper Restriction of XML External Entity ReferenceBase
- Data version
- 5.1
- Document digest
- ef81b1980762c1e3b99f2a485f73b8503d801277620c5bcffd8097abf1ad97bf
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
n/aprosodyFixed in prosody 0.11.12, Affects all versions with support for WebSockets.—