high · CVSS v3 6.5 · CVSS v4 7.1
CVE-2026-100675
stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes …
Description
stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until the API process restarts.
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- 7.1
- EPSS
- —