Logic Error in stoatchat Product Allows Database Abuse
CVE-2025-71377
8.7HIGH
What is CVE-2025-71377?
The stoatchat application prior to version 20250210-1 (0.8.2) contains a critical logic error in handling query messages. This vulnerability enables a remote unauthenticated attacker to craft specially designed requests that leverage a flaw in the message fetching mechanism. Specifically, a message limit of zero can be interpreted by the database as 'no limit', allowing attackers to retrieve an entire channel's message history in one expensive operation. This can lead to significant resource exhaustion as multiple requests can be initiated, thereby causing a denial of service. The issue has been addressed in the latest versions, emphasizing the need for users to update to secure their instances.
Affected Version(s)
stoatchat 0 < 0.8.2
stoatchat 0.8.2
