Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing because the stanza type is not checked. This is fixed in 0.22.0.
{
"nvd_published_at": "2024-09-25T01:15:44Z",
"github_reviewed": true,
"github_reviewed_at": "2024-09-25T18:27:09Z",
"severity": "CRITICAL",
"cwe_ids": [
"CWE-290"
]
}