AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-24968

MEDIUM · CVSS 5.9 EPSS 0.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-02-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-24968
Severity
MEDIUM
CVSS
5.9
EPSS
0.54%

Original NVD Description

In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.

Related CVEs

Other vulnerabilities affecting the same vendor(s)