Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mellium.im/xmpp(Go) | 0 | 0.22.0 | N/A |
CVSS Metrics