VYPR

CVE-2026-66749-Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat-

by Theopaid

CVEs (1)

  • CVE-2026-66749MedJul 28, 2026
    risk 0.00cvss 6.5epss 0.00

    Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages…