{"id":"CVE-2022-24968","aliases":["GHSA-h289-x5wc-xcv8","GHSA-m658-p24x-p74r","GO-2022-0370"],"url":"https://o3.security/vulnerability/CVE-2022-24968","summary":"Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket","details":"In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server under their control without causing TLS certificate verification to fail. This occurs because the wrong host name is selected during this verification.","published":"2022-02-11T18:16:54Z","modified":"2026-08-12T03:51:48.916402099Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00542,"percentile":0.43167,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"mellium.im/xmpp","fixedVersion":"0.21.1"}],"fix":null,"references":[{"type":"WEB","url":"https://mellium.im/cve/cve-2022-24968/"},{"type":"WEB","url":"https://mellium.im/xmpp/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24968.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24968"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.916402099Z"}}