CVE-2025-71377

⚪ Do wiadomości

Błąd logiczny w stoatchat umożliwia zdalne pobranie całej historii wiadomości, co prowadzi do odmowy usługi.

CVSS
0.0
EPSS
0.7%
Exploit
none
Vendor
Opis źródłowy (NVD)

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.7%
Opublikowano (NVD)2026-07-16 13:16:24 UTC
Ostatnia modyfikacja (NVD)2026-10-06 22:10:00 UTC
Referencje