CVE-2026-63088
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the underlying HTTP client iterates all cached addresses.
वीकनेस
stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the underlying HTTP client iterates all cached addresses.
संदर्भ
- https://github.com/stoatchat/stoatchat/releases/tag/v0.14.0
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4mcc-p83c-r77q
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-xhww-5g9p-vvq5
- https://www.vulncheck.com/advisories/stoatchat-ssrf-via-dns-based-ip-blocklist-bypass
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-4mcc-p83c-r77q
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।