oss-sec mailing list archives
ejabberd 26.07 released with several security fixes
From: Eddie Chapman <eddie () ehuk net>
Date: Wed, 5 Aug 2026 16:34:56 +0100
Greetings,I'm not in any way anything to do with ejabberd, just thought I'd post that 26.07 was released a few days ago with a large "Security fixes" section.
https://www.process-one.net/blog/ejabberd-26-07/It's notable as I've followed the project for years and can't remember the last time one of their releases had security fixes listed, let alone this many.
Copying/pasting the "Security fixes" section verbatim below, from the release announcement above, as I know this is desired on this list. I've no idea if any of these are being tracked in any security databases.
Eddie- It's possible to craft PLAIN auth request and authenticate as one user, but then open session for different one. - mod_caps persistent cache can be poisoned by using legacy version requests.This cache was only used to determine list of nodes that should trigger notifications in PubSub presence-based delivery.
- SQL injection in mod_pubsub handling of paging requests.- Possible atom exhaustion that can be triggered by issuing REST requests to mod_http_api. - It was possible to make ejabberd send redirect response for OAuth requests to unvetted url. This required enabling ejabberd to act as OAuth provider (by adding request handler for ejabberd_oauth in http listener). As part of this fix we changed oauth_client_id_check default value to db.
- using ejabberd as OAuth provider will be only allowed by clients- that were previously registered with oauth_add_client_password or oauth_add_client_implicit commands. - Tokens generated by mod_bosh, captcha, mod_auth_fast, mod_http_upload and mod_invites used not cryptographically strong random number generators.
- Files server by mod_http_upload didn't have XSS prevention headers. - Issues in authentication of SIP requests. - Request to web_admin were lacking CSRF protection. - It was possible to skip captcha verification in mod_register_web. - mod_conversejs allowed putting unescaped value from url in page content.
Current thread:
- ejabberd 26.07 released with several security fixes Eddie Chapman (Aug 05)
