{"id":"CVE-2016-10027","aliases":["GHSA-66pq-hqv5-228g"],"url":"https://o3.security/vulnerability/CVE-2016-10027","summary":"Smack allows the bypass of TLS protections","details":"Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the \"starttls\" feature from a server response.","published":"2017-01-12T23:59:00.197Z","modified":"2026-07-08T12:35:27.683755Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.igniterealtime.smack:smack-core","fixedVersion":"4.1.9"}],"fix":{"url":"https://github.com/igniterealtime/Smack/commit/059ee99ba0d5ff7758829acf5a9aeede09ec820b","label":"igniterealtime/Smack@059ee99"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4WXAZ4JVJXHMEDDXJVWJHPVBF5QCTZF/"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95129"},{"type":"ADVISORY","url":"https://community.igniterealtime.org/blogs/ignite/2016/11/22/smack-security-advisory-2016-11-22"},{"type":"REPORT","url":"https://issues.igniterealtime.org/projects/SMACK/issues/SMACK-739"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/12/22/12"},{"type":"FIX","url":"https://github.com/igniterealtime/Smack/commit/059ee99ba0d5ff7758829acf5a9aeede09ec820b"},{"type":"FIX","url":"https://github.com/igniterealtime/Smack/commit/a9d5cd4a611f47123f9561bc5a81a4555fe7cb04"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10027"},{"type":"PACKAGE","url":"https://github.com/igniterealtime/Smack"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J4WXAZ4JVJXHMEDDXJVWJHPVBF5QCTZF"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J4WXAZ4JVJXHMEDDXJVWJHPVBF5QCTZF"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:35:27.683755Z"}}