Username Validation Bypass in Stoatchat Prior to Version 0.15.5
CVE-2026-100674

5.3MEDIUM

Key Information:

Vendor

Stoatchat

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100674?

The Stoatchat application prior to version 0.15.5 has a vulnerability that permits attackers to circumvent the intended username validation process. This occurs due to improper handling of Unicode characters, allowing the creation of usernames that should be blocked by character allowlists and length restrictions. Attackers can exploit this flaw to create reserved-name lookalikes, embed unauthorized special characters, and exceed the 32-character storage limit, thereby undermining the integrity and security of user accounts.

Affected Version(s)

stoatchat 0 < 0.15.5

stoatchat 0.15.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.