Pidgin-OTR can leak real JID information with XMPP groupchat
XMPP MUC (XEP-0045) supports anonymous and semi-anonymous rooms, such that no-one except the server can see the real JID for a specific nickname in a group chat - or only moderators can see it. The specification also allows for the group chat server to mediate private messages from one person in the room to another person in the room. If a user has the Pidgin OTR plugin turned on, the default behavior will mean that it is possible to de-anonymize users in an anonymous or semi-anonymous room if you have ever interacted with them before using OTR, since the key used will be the same even though the group nick name is used. This is probably very unexpected behavior and can potentially be a serious information leak.