Skip to content

Update module mellium.im/xmpp to v0.22.0 [SECURITY]#584

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-mellium.im-xmpp-vulnerability
Open

Update module mellium.im/xmpp to v0.22.0 [SECURITY]#584
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-mellium.im-xmpp-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Sep 25, 2024

This PR contains the following updates:

Package Change Age Confidence
mellium.im/xmpp v0.21.4v0.22.0 age confidence

Mellium allows Authentication Bypass by Spoofing

CVE-2024-46957 / GHSA-98hf-m87w-cq6h

More information

Details

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0.

Severity

  • CVSS Score: 9.3 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Sep 25, 2024

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
mellium.im/sasl v0.3.1 -> v0.3.2

@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 568bb27 to 4a64753 Compare October 12, 2024 15:19
@codecov
Copy link
Copy Markdown

codecov Bot commented Oct 12, 2024

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 40.42%. Comparing base (2528a15) to head (394793e).
⚠️ Report is 7 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #584      +/-   ##
==========================================
- Coverage   40.57%   40.42%   -0.16%     
==========================================
  Files          91       91              
  Lines        7206     7223      +17     
==========================================
- Hits         2924     2920       -4     
- Misses       3993     4013      +20     
- Partials      289      290       +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 4a64753 to 321ba8d Compare November 17, 2024 16:53
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 321ba8d to 1f77207 Compare December 22, 2024 16:04
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 1f77207 to 8c332de Compare March 3, 2025 14:31
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 8c332de to e492be8 Compare March 11, 2025 12:14
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from e492be8 to 90cfb26 Compare April 8, 2025 12:23
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 90cfb26 to ba672aa Compare May 7, 2025 17:47
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from ba672aa to 8d4b434 Compare May 25, 2025 11:26
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 8d4b434 to 285eb36 Compare September 21, 2025 14:16
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 285eb36 to 3af64ed Compare October 9, 2025 15:24
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Dec 15, 2025

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
mellium.im/sasl v0.3.1 -> v0.3.2

@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 3af64ed to 408823d Compare December 15, 2025 18:30
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 408823d to aa408b1 Compare February 2, 2026 21:03
@renovate renovate Bot changed the title fix(deps): update module mellium.im/xmpp to v0.22.0 [security] fix(deps): update module mellium.im/xmpp to v0.22.0 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/go-mellium.im-xmpp-vulnerability branch March 27, 2026 00:52
@renovate renovate Bot changed the title fix(deps): update module mellium.im/xmpp to v0.22.0 [security] - autoclosed fix(deps): update module mellium.im/xmpp to v0.22.0 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch 2 times, most recently from aa408b1 to 4ff168a Compare March 30, 2026 20:30
@renovate renovate Bot changed the title fix(deps): update module mellium.im/xmpp to v0.22.0 [security] Update module mellium.im/xmpp to v0.22.0 [SECURITY] Apr 8, 2026
@renovate renovate Bot changed the title Update module mellium.im/xmpp to v0.22.0 [SECURITY] Update module mellium.im/xmpp to v0.22.0 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update module mellium.im/xmpp to v0.22.0 [SECURITY] - autoclosed Update module mellium.im/xmpp to v0.22.0 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch 2 times, most recently from 4ff168a to 394793e Compare April 27, 2026 23:45
@renovate renovate Bot force-pushed the renovate/go-mellium.im-xmpp-vulnerability branch from 394793e to 3b82ee5 Compare May 12, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants