{"api_version":"1","generated_at":"2026-07-23T13:39:56+00:00","cve":"CVE-2009-3026","urls":{"html":"https://cve.report/CVE-2009-3026","api":"https://cve.report/api/cve/CVE-2009-3026.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3026","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3026"},"summary":{"title":"CVE-2009-3026","description":"protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the \"require TLS/SSL\" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-08-31 20:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-310","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37071","name":"http://secunia.com/advisories/37071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo update for pidgin - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279","name":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"404 Not Found","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#542891 - libpurple connects without encryption while \"require TLS/SSL\" is enabled - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53000","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/08/24/2","name":"http://www.openwall.com/lists/oss-security/2009/08/24/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE id request: pidgin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://developer.pidgin.im/ticket/8131","name":"http://developer.pidgin.im/ticket/8131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#8131 (SSL/TLS bug due to old servers that don't follow xmpp spec)\n     –\n      Pidgin – Trac","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36368","name":"http://www.securityfocus.com/bid/36368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pidgin 'protocols/jabber/auth.c' JABBER Server XMPP Specifications Man In The Middle Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3026","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3026","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3026","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pidgin","cpe5":"pidgin","cpe6":"2.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-3026","organization":"Red Hat","lastmodified":"2009-09-22","contributor":"Mark J Cox","statementText":"Red Hat has released updates to correct this issue: https://rhn.redhat.com/errata/RHSA-2009-1453.html","cve_year":"2009","cve_id":"3026","crc32":"bc3406ee"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:14:55.553Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36368","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36368"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://developer.pidgin.im/ticket/8131"},{"name":"37071","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37071"},{"name":"[oss-security] 20090824 CVE id request: pidgin","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/08/24/2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891"},{"name":"pidgin-libpurple-weak-security(53000)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53000"},{"name":"oval:org.mitre.oval:def:5757","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757"},{"name":"oval:org.mitre.oval:def:11070","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-08-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the \"require TLS/SSL\" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"36368","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36368"},{"tags":["x_refsource_CONFIRM"],"url":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279"},{"tags":["x_refsource_CONFIRM"],"url":"http://developer.pidgin.im/ticket/8131"},{"name":"37071","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37071"},{"name":"[oss-security] 20090824 CVE id request: pidgin","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/08/24/2"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891"},{"name":"pidgin-libpurple-weak-security(53000)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53000"},{"name":"oval:org.mitre.oval:def:5757","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757"},{"name":"oval:org.mitre.oval:def:11070","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3026","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the \"require TLS/SSL\" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36368","refsource":"BID","url":"http://www.securityfocus.com/bid/36368"},{"name":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279","refsource":"CONFIRM","url":"http://developer.pidgin.im/viewmtn/revision/diff/312e056d702d29379ea61aea9d27765f127bc888/with/55897c4ce0787edc1e7721b7f4a9b5cbc8357279"},{"name":"http://developer.pidgin.im/ticket/8131","refsource":"CONFIRM","url":"http://developer.pidgin.im/ticket/8131"},{"name":"37071","refsource":"SECUNIA","url":"http://secunia.com/advisories/37071"},{"name":"[oss-security] 20090824 CVE id request: pidgin","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/08/24/2"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891","refsource":"CONFIRM","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=542891"},{"name":"pidgin-libpurple-weak-security(53000)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53000"},{"name":"oval:org.mitre.oval:def:5757","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5757"},{"name":"oval:org.mitre.oval:def:11070","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11070"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3026","datePublished":"2009-08-31T20:00:00.000Z","dateReserved":"2009-08-31T00:00:00.000Z","dateUpdated":"2024-08-07T06:14:55.553Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-08-31 20:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-310","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pidgin:pidgin:2.6.0:*:*:*:*:*:*:*","matchCriteriaId":"A8321D92-B935-4C2A-81B1-5984BFF4FD57"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3026","Ordinal":"1","Title":"CVE-2009-3026","CVE":"CVE-2009-3026","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3026","Ordinal":"1","NoteData":"protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the \"require TLS/SSL\" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.","Type":"Description","Title":"CVE-2009-3026"},{"CveYear":"2009","CveId":"3026","Ordinal":"2","NoteData":"2009-08-31","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3026","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}