Denial of Service Vulnerability in Stoatchat by Stoatchat Inc.
CVE-2026-100675

7.1HIGH

Key Information:

Vendor

Stoatchat

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100675?

Stoatchat versions prior to 0.15.5 are susceptible to a denial of service vulnerability linked to the acknowledgement worker responsible for processing mass mention messages. Authenticated users can exploit this flaw by sending five specially crafted role-mention messages, effectively terminating all acknowledgement workers. As a result, the service experiences disruptions in push notifications and the deployment of mention badges across the platform until the API process is manually restarted.

Affected Version(s)

stoatchat 0 < 0.15.5

stoatchat 0.15.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

QuentinRa
.