CVE-2026-73058

Summary

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.

Affected Software

VendorProductVersion RangeStatus
stoatchatstoatchat0 < 0.15.0affected
stoatchatstoatchat0.15.0unaffected

Weaknesses

  • CWE-918: Server-Side Request Forgery (SSRF)

References