PT-2026-60519 · Stoatchat · Stoatchat
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
stoatchat versions prior to 0.14.0
Description
An unauthenticated network-accessible attacker can perform a server-side request forgery (SSRF) by bypassing the DNS-based IP blocklist. This occurs due to incomplete address validation within the
url is blacklisted() function, which only inspects the first resolved address, whereas the underlying HTTP client iterates through all cached addresses.Recommendations
Update to version 0.14.0 or later.
As a temporary mitigation, restrict access to the
url is blacklisted() function or the components utilizing it to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stoatchat