CVE-2026-100678
stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.
| CWE | CWE-307 |
| Vendor | stoatchat |
| Product | stoatchat |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for stoatchat stoatchat
Be the first to know when new medium vulnerabilities affecting stoatchat stoatchat are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
stoatchat / stoatchat
0 < 0.15.5
References
Credits
๐ QuentinRa