Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-73057: stoatchat before 0.15.0 Memory Exhaustion Denial of Service
CVE-2026-73057 · published 18 days ago
Summary
The stoatchat software before version 0.15.0 is vulnerable to a denial of service attack. An attacker can exploit this vulnerability by hosting malicious SVG files with large dimensions, which can cause the software to run out of memory. To protect your system, update stoatchat to version 0.15.0 or later.
What to do
- Update stoatchat stoatchat to version 0.15.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| stoatchat | stoatchat | < 0.15.0 |
Original advisory text
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with ex...
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
References
Severity
8.7
High
CVSS 3.1: 7.5 (MITRE)
Exploitation
EPSS <1%
Type
CWE-400Uncontrolled Resource Consumption
Timeline
Published16 Aug 2026
Updated29 Aug 2026
First seen16 Aug 2026
Monitor software like this
Free during beta