PT-2026-73145 · Stoatchat · Stoatchat

·

CVE-2026-73058

·

Published

2026-08-16

·

Updated

2026-08-16

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stoatchat versions prior to 0.15.0
Description An issue exists where the SSRF (Server-Side Request Forgery) blocklist fails to block the IPv6 unspecified address (::). This allows unauthenticated attackers to bypass protections using the '/proxy' and '/embed' endpoints. By crafting requests with IPv6 literal syntax, attackers can access services on the loopback interface to retrieve sensitive internal content.
Recommendations Update to version 0.15.0 or later. Restrict access to the '/proxy' and '/embed' endpoints as a temporary mitigation measure.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73058
GHSA-4RMR-77QV-HQ47

Affected Products

Stoatchat