MEDIUM 6.9 NVD
CVE-2026-73058
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.
References
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4rmr-77qv-hq47
- https://www.vulncheck.com/advisories/stoatchat-before-ssrf-via-ipv6-unspecified-address-by
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-16 via NVD.
vulnfeed aggregates 11848 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.