PatchSiren cyber security CVE debrief
CVE-2017-5591 Poezio CVE debrief
CVE-2017-5591 describes an XMPP client trust failure in Message Carbons handling. In affected versions, a remote attacker may cause the application to display messages as if they came from another user, including a contact, which can mislead users and support social engineering. The official NVD data ties the issue to SleekXMPP up to 1.3.1, Slixmpp up to 1.2.3, and Poezio 0.8 through 0.10 as bundled with those libraries.
- Vendor
- Poezio
- Product
- Unknown
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Poezio users and deployers, XMPP client maintainers, and security teams responsible for messaging endpoints should review this issue, especially where users rely on displayed sender identity for trust decisions.
Technical summary
The flaw is an incorrect implementation of XEP-0280 Message Carbons. NVD classifies it under CWE-20 and CWE-346 and scores it CVSS 3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N. The practical impact is integrity loss in the chat UI: a remote party can influence what sender identity the client displays, enabling impersonation-style social engineering without affecting confidentiality or availability.
Defensive priority
Medium. The bug does not indicate code execution or data theft, but it can undermine message authenticity and user trust in a communications client, which is high-value in phishing and impersonation scenarios.
Recommended defensive actions
- Upgrade SleekXMPP to a version newer than 1.3.1 and Slixmpp to a version newer than 1.2.3, or use a Poezio release that bundles patched dependencies.
- If you operate Poezio 0.8, 0.8.1, 0.9, or 0.10, verify the bundled XMPP library versions and confirm they are not in the vulnerable ranges.
- Review message-rendering and Message Carbons handling so the client does not present untrusted carboned messages as if they originated from a different user.
- Where immediate upgrading is not possible, reduce reliance on displayed identity cues for sensitive decisions until patched.
Evidence notes
This debrief is based on the supplied NVD record and referenced advisories/patch links. The source corpus states the affected versions (SleekXMPP <= 1.3.1, Slixmpp <= 1.2.3, Poezio 0.8/0.8.1/0.9/0.10), the issue class (incorrect XEP-0280 implementation), the likely impact (impersonation in the display leading to social engineering), and the NVD CVSS/CWE metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5591 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5591
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5591 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5591
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/
[email protected] - Exploit, Technical Description, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
[email protected] - Exploit, Technical Description, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.