CVE-2026-100675: stoatchat before 0.15.5 Denial of Service via mass mentions

Published Sep 26, 2026
·
Updated

stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until the API process restarts.

Affected Software

1 affected component
stoatchat<0.15.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade stoatchat to a version that resolves this vulnerability.

    Fixed in 0.15.5

Event History

Sep 26, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Jul 10, 58707
Event
via NVD·07:23 PM

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user can exploit it. The attack requires the ability to send crafted role-mention messages; no user interaction is required.

2

What is the operational impact if exploitation succeeds?

Five crafted role-mention messages can terminate all acknowledgement workers. Push notifications and mention badges are then disabled across the deployment until the API process restarts.

3

Are deployments on the affected version range exposed by default?

The provided information identifies the acknowledgement worker's processing of mass mention messages as the affected path, but it does not state whether role mentions or the affected worker are enabled in a default configuration.

4

How can administrators recover if they cannot patch immediately?

Restarting the API process restores the acknowledgement workers after an attack. The provided information does not identify a mitigation that prevents authenticated users from triggering the condition before upgrading.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203