CVE-2026-73058 PUBLISHED

stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass

Assigner: VulnCheck
Reserved: 10.08.2026 Published: 16.08.2026 Updated: 16.08.2026

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor stoatchat
Product stoatchat
Versions Default: unaffected
  • affected from 0 to 0.15.0 (excl.)
  • Version 0.15.0 is unaffected

Credits

  • DonAsako reporter

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE