Username Validation Bypass in Stoatchat Prior to Version 0.15.5
CVE-2026-100674
5.3MEDIUM
What is CVE-2026-100674?
The Stoatchat application prior to version 0.15.5 has a vulnerability that permits attackers to circumvent the intended username validation process. This occurs due to improper handling of Unicode characters, allowing the creation of usernames that should be blocked by character allowlists and length restrictions. Attackers can exploit this flaw to create reserved-name lookalikes, embed unauthorized special characters, and exceed the 32-character storage limit, thereby undermining the integrity and security of user accounts.
Affected Version(s)
stoatchat 0 < 0.15.5
stoatchat 0.15.5
