FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

ejabberd -- Potential DDoS in XML Parser

Affected packages
ejabberd < 26.04

Details

VuXML ID 82064ab5-3d76-11f1-89ab-901b0e9408dc
Discovery 2026-04-20
Entry 2026-04-21

ejabberd team reports:

This release adds new options that limit max memory used by XML parser used to process XMPP payloads, to prevent potential Denial of Service attack. The default values for pre-auth provide sufficient protection for ejabberd against non-authenticated users on c2s and s2s, so there is no need to change your configuration.

References

URL https://www.process-one.net/blog/ejabberd-26-04/