high · CVSS v3 6.5 · CVSS v4 8.3
CVE-2026-100678
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn…
Description
stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.
Scores
- Severity
- high
- CVSS v2
- 6.1
- CVSS v3
- 6.5
- CVSS v4
- 8.3
- EPSS
- —