Product
high
advisory
Denial of Service via SVG ViewBox Exploitation in stoatchat
2 TTPs 1 CVEstoatchat versions prior to 0.15.0 contain an uncontrolled resource consumption vulnerability in its proxy endpoint that allows unauthenticated attackers to cause memory exhaustion through malicious SVG files.
stoatchat
denial-of-service
cve
vulnerability
authorization-bypass
cve-2026-74869
privacy
2t
1c
updated
high
advisory
Unauthenticated Server-Side Request Forgery (SSRF) Vulnerability in stoatchat CVE-2026-63306
1 rule 3 TTPs 1 CVEAn unauthenticated server-side request forgery vulnerability, tracked as CVE-2026-63306, exists in stoatchat versions prior to 0.13.5 in the /proxy and /embed endpoints, allowing attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints, leading to unauthorized information disclosure and potential further compromise of internal infrastructure.
stoatchat
ssrf
vulnerability
web-application
unauthenticated
information-disclosure
1r
3t
1c