Vendor
Denial of Service via SVG ViewBox Exploitation in stoatchat
2 TTPs 1 CVEstoatchat versions prior to 0.15.0 contain an uncontrolled resource consumption vulnerability in its proxy endpoint that allows unauthenticated attackers to cause memory exhaustion through malicious SVG files.
CVE-2026-63088: stoatchat Server-Side Request Forgery (SSRF) via DNS Blocklist Bypass
1 TTP 1 CVEAn unauthenticated, network-accessible Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63088, exists in stoatchat versions prior to 0.14.0, allowing attackers to bypass DNS-based IP blocklists by exploiting incomplete address validation, potentially leading to unauthorized access to internal network resources.
Unauthenticated Server-Side Request Forgery (SSRF) Vulnerability in stoatchat CVE-2026-63306
1 rule 3 TTPs 1 CVEAn unauthenticated server-side request forgery vulnerability, tracked as CVE-2026-63306, exists in stoatchat versions prior to 0.13.5 in the /proxy and /embed endpoints, allowing attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints, leading to unauthorized information disclosure and potential further compromise of internal infrastructure.