CVE-2026-73057: stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service
Published Aug 16, 2026
·Updated
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
Affected Software
1 affected component
stoatchat<0.15.0
Event History
Aug 16, 2026
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73057?
CVE-2026-73057 has a severity rating of high, with a score of 7.5.
2
What does CVE-2026-73057 affect?
CVE-2026-73057 affects stoatchat versions prior to 0.15.0.
3
How does CVE-2026-73057 exploit occur?
CVE-2026-73057 exploits the lack of validation of SVG viewBox dimensions, which can lead to denial of service through memory exhaustion.
4
How do I fix CVE-2026-73057?
To fix CVE-2026-73057, upgrade stoatchat to version 0.15.0 or later.
5
What type of vulnerability is CVE-2026-73057?
CVE-2026-73057 is classified as a denial of service vulnerability.