stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-16 14:16
Updated : 2026-08-18 15:17
NVD link : CVE-2026-73057
Mitre link : CVE-2026-73057
CVE.ORG link : CVE-2026-73057
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
