Stoatchat 0.15.5 之前版本存在一个拒绝服务(DoS)漏洞,该漏洞位于处理大规模提及消息的确认工作器(acknowledgement worker)中。经过身份验证的用户可以发送五条精心构造的角色提及消息,导致所有确认工作器终止,从而在全局范围内禁用推送通知和提及徽章功能,直到 API 进程重启。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100679 | 8.8 HIGH | stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket |
| CVE-2026-100676 | 8.2 HIGH | stoatchat before 0.15.5 Local Filesystem Read via SVG |
| CVE-2026-100678 | 6.5 MEDIUM | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting |
| CVE-2026-100677 | 5.3 MEDIUM | stoatchat before 0.15.5 Account Enumeration via Error Location |
| CVE-2026-100674 | 4.3 MEDIUM | stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization |
No comments yet