What is CVE-2026-73058?
This vulnerability exists because stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist. Unauthenticated attackers can bypass protections via the /proxy and /embed endpoints to access services on the loopback interface. Upgrading to version 0.15.0 or later is recommended.
Azərbaycanca: Bu zəiflik stoatchat-ın 0.15.0-dan əvvəlki versiyalarında SSRF müdafiə siyahısında IPv6 təyin olunmamış ünvanının (::) bloklanmaması səbəbindən yaranır. Autentifikasiya olunmamış hücumçular /proxy və /embed endpoint-ləri vasitəsilə loopback interfeysindəki servislərə giriş əldə edə bilər. Tətbiqi 0.15.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of stoatchat are affected by CVE-2026-73058?
This vulnerability affects stoatchat versions before 0.15.0.
What can an attacker achieve by exploiting CVE-2026-73058?
Unauthenticated attackers can gain access to services on the loopback interface via the /proxy and /embed endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.