What is CVE-2026-73057?
CVE-2026-73057: A vulnerability in Stoatchat versions before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint. This allows attackers to cause a denial of service by memory exhaustion through hosting malicious SVGs with extremely large dimensions and triggering concurrent requests. Affected systems should be upgraded to version 0.15.0 or later.
Azərbaycanca: CVE-2026-73057: Stoatchat-in 0.15.0 versiyasından əvvəlki proxy endpoint-də SVG viewBox ölçülərinin yoxlanılmaması zəifliyi aşkarlanıb. Bu, təcavüzkara həddindən artıq böyük ölçülü zərərli SVG-lər host edib paralel sorğularla yaddaşı tükəndirərək denial of service hücumu həyata keçirməyə imkan verir. Təsirə məruz qalan sistemlərdə Stoatchat-i 0.15.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which component of Stoatchat was the CVE-2026-73057 vulnerability discovered?
The vulnerability is related to the lack of validation of SVG viewBox dimensions in the proxy endpoint.
Which version is recommended to upgrade to in order to mitigate CVE-2026-73057?
It is recommended to upgrade affected systems to Stoatchat version 0.15.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.