PT-2026-60519 · Stoatchat · Stoatchat

·

CVE-2026-63088

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.14.0
Description An unauthenticated network-accessible attacker can perform a server-side request forgery (SSRF) by bypassing the DNS-based IP blocklist. This occurs due to incomplete address validation within the url is blacklisted() function, which only inspects the first resolved address, whereas the underlying HTTP client iterates through all cached addresses.
Recommendations Update to version 0.14.0 or later. As a temporary mitigation, restrict access to the url is blacklisted() function or the components utilizing it to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63088
GHSA-4MCC-P83C-R77Q
GHSA-XHWW-5G9P-VVQ5

Affected Products

Stoatchat