HIGH 8.3 NVD
CVE-2026-100678
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with o
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.
References
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-6877-g673-f5r8
- https://www.vulncheck.com/advisories/stoatchat-before-0.15.5-mfa-brute-force-via-insuffici
This high severity vulnerability with a CVSS score of 8.3 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11675 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.