Denial of Service Vulnerability in Stoatchat by Stoatchat Inc.
CVE-2026-100675
7.1HIGH
What is CVE-2026-100675?
Stoatchat versions prior to 0.15.5 are susceptible to a denial of service vulnerability linked to the acknowledgement worker responsible for processing mass mention messages. Authenticated users can exploit this flaw by sending five specially crafted role-mention messages, effectively terminating all acknowledgement workers. As a result, the service experiences disruptions in push notifications and the deployment of mention badges across the platform until the API process is manually restarted.
Affected Version(s)
stoatchat 0 < 0.15.5
stoatchat 0.15.5
