← Back to the live CVE advisory feed

CVE-2026-100676: stoatchat

Severity
8.8 (HIGH)
Vendor
STOATCHAT
Affected versions
0 through before 0.15.5
Fixed version
0.15.5
Patch status
Patched
Published
2026-09-26T14:16:51.577
Modified
2026-09-26T14:16:51.577

Why it matters

This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.
  • Review logs for suspicious activity related to the affected application or component.

Technical summary

January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG values as local filesystem paths when a fetched resource is served as image/svg+xml. An unauthenticated remote attacker who causes the service to proxy an attacker-hosted SVG (e.g. via the /proxy endpoint) can determine whether local files exist through observable response-time differences, and can cause supported local image files to be disclosed after re-encoding. Because each referenced file is read in full with no effective limit on the number or total volume of reads, a single request can also generate an unbounded amount of local filesystem I/O and memory pressure (the published proof of concept drives about 4.34 GB of reads), leading to denial of service. The issue is fixed in 0.15.5.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 26, 2026 04:00 PM UTC
416 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-100382
Mediawiki – ExternalData Extension PATCH
Reporter: C4F26CC8-17FF-4C99-B5E2-38FC1793EACC
10
CRITICAL
VIEW RECORD
CVE-2026-97163
UP plugin for Joomla
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-92161
oauth PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-18143
Request a Quote for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94132
AcyMailing Enterprise extension for Joomla PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-48482
glpi PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-100706
kyverno PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100714
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100716
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-97160
UP plugin for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-97063
X-SpringBoot
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-97064
X-SpringBoot
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-100720
froxlor PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-94130
YouTube Gallery extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-100389
GestSup PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100606
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100607
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100684
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-97161
UP plugin for Joomla
Reporter: SECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-39353
InvoicePlane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-42322
Piwigo PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-62262
Piwigo
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-84458
zammad PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-100390
Product identification pending
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-100551
OpenClaw PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-100567
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-100683
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-94445
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-61525
zammad PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-100391
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-96795
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-100597
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-100676
stoatchat PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-89032
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-56725
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-56733
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-100520
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100544
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100552
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100557
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100558
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100568
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100575
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100580
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100586
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100587
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100588
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100589
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100596
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100599
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100603
clawhub PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100608
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100614
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100615
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100617
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100618
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100619
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100622
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100623
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100625
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100628
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100631
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100644
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100656
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100657
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100660
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100661
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100662
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100663
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100664
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100665
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100669
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100670
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100672
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100682
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100689
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100690
hugo PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100692
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100700
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100711
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84462
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-97060
X-SpringBoot
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100372
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100559
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100561
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100585
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100612
capgo.app
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100639
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100640
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100641
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100645
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100646
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100671
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100680
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100686
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100693
hugo PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-47679
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-55214
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-71483
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-100530
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.