CVSS
5.8
CVSS v3.1
EPSS
N/A
Exploit Prediction Score
Published
August 16, 2026
Exploitability
No EPSS data available
stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).