CVE-2026-100675
Received Received - Intake

Denial of Service in StoaChat via Role-Mention Messages

Vulnerability report for CVE-2026-100675, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until the API process restarts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
stoatchat stoatchat to 0.15.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in stoatchat versions before 0.15.5. Authenticated users can exploit it by sending five crafted role-mention messages, which terminate all acknowledgement workers. This disables push notifications and mention badges across the entire deployment until the API process restarts.

Detection Guidance

Detecting this vulnerability requires monitoring for excessive role-mention messages or failed acknowledgement worker processes. Check logs for repeated mention-related errors or worker crashes. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability can disrupt push notifications and mention badges for all users in the affected stoatchat deployment. This could lead to missed alerts, reduced functionality, and operational downtime until the system is manually restarted.

Mitigation Strategies

Upgrade stoatchat to version 0.15.5 or later to patch the vulnerability. Temporarily restrict role-mention permissions for users until the update is applied. Monitor worker processes for unexpected terminations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100675. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart