stoatchat
stoatchat
| Version / range | Status | Type |
|---|---|---|
| 0 to before 0.15.5 | affected | semver |
| 0.15.5 | unaffected | semver |
stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until the API process restarts.
Risk score
7.1
CVSS 4.0
stoatchat
| Version / range | Status | Type |
|---|---|---|
| 0 to before 0.15.5 | affected | semver |
| 0.15.5 | unaffected | semver |
7.1
CVSS 4.0
6.5
CVSS 3.1