{"id":"CVE-2011-2532","details":"The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.","modified":"2026-04-10T03:41:52.088034Z","published":"2011-06-22T21:55:02Z","references":[{"type":"FIX","url":"http://blog.prosody.im/prosody-0-8-1-released/"},{"type":"FIX","url":"http://hg.prosody.im/0.8/rev/20979f124ad9"},{"type":"FIX","url":"http://prosody.im/doc/release/0.8.1"}],"schema_version":"1.7.5"}