CVE-2025-71377 - CVE House
Back to Database
Status published High CVE-2025-71377

stoatchat before 20250210-1 Unrestricted Message History Fetch

Vulnerability Description

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71377

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stoatchat
Vulnerable Versions:
0, 20250210-1 (0.8.2)

Timeline

Official Publish: July 16th, 2026
Last Modified: July 16th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.