High severity8.6NVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
CVE-2026-63088
CVE-2026-63088
Description
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the underlying HTTP client iterates all cached addresses.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.