Logic Error in stoatchat Product Allows Database Abuse
CVE-2025-71377

8.7HIGH

Key Information:

Vendor

Stoatchat

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2025-71377?

The stoatchat application prior to version 20250210-1 (0.8.2) contains a critical logic error in handling query messages. This vulnerability enables a remote unauthenticated attacker to craft specially designed requests that leverage a flaw in the message fetching mechanism. Specifically, a message limit of zero can be interpreted by the database as 'no limit', allowing attackers to retrieve an entire channel's message history in one expensive operation. This can lead to significant resource exhaustion as multiple requests can be initiated, thereby causing a denial of service. The issue has been addressed in the latest versions, emphasizing the need for users to update to secure their instances.

Affected Version(s)

stoatchat 0 < 0.8.2

stoatchat 0.8.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.