CVE-2026-63306

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.
Configurations

No configuration.

History

16 Jul 2026, 14:16

Type Values Removed Values Added
References () https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5 - () https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5 -

16 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-16 13:16

Updated : 2026-07-16 14:16


NVD link : CVE-2026-63306

Mitre link : CVE-2026-63306

CVE.ORG link : CVE-2026-63306


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)