Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <fc8a17b4-08be-423e-8f42-fc60cab03a0c@ehuk.net>
Date: Wed, 5 Aug 2026 16:34:56 +0100
From: Eddie Chapman <eddie@...k.net>
To: oss-security@...ts.openwall.com
Subject: ejabberd 26.07 released with several security fixes

Greetings,

I'm not in any way anything to do with ejabberd, just thought I'd post 
that 26.07 was released a few days ago with a large "Security fixes" 
section.

https://www.process-one.net/blog/ejabberd-26-07/

It's notable as I've followed the project for years and can't remember 
the last time one of their releases had security fixes listed, let alone 
this many.

Copying/pasting the "Security fixes" section verbatim below, from the 
release announcement above, as I know this is desired on this list. I've 
no idea if any of these are being tracked in any security databases.

Eddie

- It's possible to craft PLAIN auth request and authenticate as one 
user, but then open session for different one.
- mod_caps persistent cache can be poisoned by using legacy version 
requests.This cache was only used to determine list of nodes that should 
trigger notifications in PubSub presence-based delivery.
- SQL injection in mod_pubsub handling of paging requests.
- Possible atom exhaustion that can be triggered by issuing REST 
requests to mod_http_api.
- It was possible to make ejabberd send redirect response for OAuth 
requests to unvetted url. This required enabling ejabberd to act as 
OAuth provider (by adding request handler for ejabberd_oauth in http 
listener). As part of this fix we changed oauth_client_id_check default 
value to db.
- using ejabberd as OAuth provider will be only allowed by clients
- that were previously registered with oauth_add_client_password or 
oauth_add_client_implicit commands.
- Tokens generated by mod_bosh, captcha, mod_auth_fast, mod_http_upload 
and mod_invites used not cryptographically strong random number generators.
- Files server by mod_http_upload didn't have XSS prevention headers.
- Issues in authentication of SIP requests.
- Request to web_admin were lacking CSRF protection.
- It was possible to skip captcha verification in mod_register_web.
- mod_conversejs allowed putting unescaped value from url in page content.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.