๐Ÿ” CVE Alert

CVE-2026-73058

MEDIUM 5.8

stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass

CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.

CWE CWE-918
Vendor stoatchat
Product stoatchat
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for stoatchat stoatchat

Be the first to know when new medium vulnerabilities affecting stoatchat stoatchat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

stoatchat / stoatchat
0 < 0.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4rmr-77qv-hq47 vulncheck.com: https://www.vulncheck.com/advisories/stoatchat-before-ssrf-via-ipv6-unspecified-address-bypass

Credits

๐Ÿ” DonAsako