CVE-2026-63306: stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63306?
CVE-2026-63306 has a severity rating of high, with a score of 8.6.
How does CVE-2026-63306 impact stoatchat?
CVE-2026-63306 allows unauthenticated server-side request forgery via the /proxy and /embed endpoints in stoatchat.
What can attackers do with CVE-2026-63306?
Attackers can exploit CVE-2026-63306 to enumerate internal services and fingerprint applications.
How do I fix CVE-2026-63306?
To mitigate CVE-2026-63306, upgrade stoatchat to version 0.13.5 or later.
What is the nature of the vulnerability in CVE-2026-63306?
CVE-2026-63306 is an unauthenticated server-side request forgery (SSRF) vulnerability.