CVE-2025-71377
stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.67%
- CWE
- CWE-1025
- Published
- 2026-07-16
- Last modified
- 2026-07-20
Affected products
- stoatchat stoatchat
- stoatchat stoatchat
- stoatchat stoatchat
Weakness type
Related vulnerabilities
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2026-9800 — Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
- CVE-2026-40880 — Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
- CVE-2026-40227 — In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with...
- CVE-2026-21691 — iccDEV has Type Confusion in CIccTag:IsTypeCompressed()