An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the original XMPP service domain, allowing the attacker to take over control over the XMPP connection and to obtain user credentials and all communication content. This is similar to CVE-2022-24968.
Cite this page
CVE-2022-26491. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-26491
Use CWE-295, Pidgin vendor hub and Pidgin product page to widen CVE-2022-26491 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-1000030, CVE-2016-2378 and CVE-2016-2377 for nearby disclosures in the same product family.