stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-16 14:16
Updated : 2026-08-31 20:30
NVD link : CVE-2026-73058
Mitre link : CVE-2026-73058
CVE.ORG link : CVE-2026-73058
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
