SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-73058

MEDIUM · CVSS 5.8 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Versions of stoatchat prior to 0.15.0 are vulnerable due to inadequate blocking of the IPv6 unspecified address (::) in the SSRF blocklist, enabling unauthenticated attackers to exploit the /proxy and /embed endpoints. This vulnerability allows attackers to craft requests that access internal services on the loopback interface, potentially exposing sensitive content. Organizations using affected versions should prioritize updating their software to mitigate the risk of unauthorized access to internal resources.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73058
Severity
MEDIUM
CVSS
5.8
EPSS
0.24%

Original NVD Description

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.