{"id":"CVE-2011-4320","details":"The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.","aliases":["GHSA-2h3q-v47h-f4rc"],"modified":"2026-04-10T03:42:04.243551Z","published":"2012-02-18T00:55:02Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/46915"},{"type":"FIX","url":"https://support.process-one.net/browse/EJAB-1498"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/11/19/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/11/19/2"},{"type":"WEB","url":"http://www.osvdb.org/77302"},{"type":"WEB","url":"http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_2.1.9"}],"schema_version":"1.7.5"}