CVE-2026-73058
EUVD-2026-5994416.08.2026, 14:16
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.
Awaiting analysis
This vulnerability is currently awaiting analysis.