rootpwn

high · CVSS v3 6.5 · CVSS v4 8.3

CVE-2026-100678

stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn…

Description

stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.

Scores

Severity
high
CVSS v2
6.1
CVSS v3
6.5
CVSS v4
8.3
EPSS
—

← All CVEs