stoatchat Delta Logic Error in Message Query Route Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in stoatchat (delta) versions prior to 20250210-1 (0.8.2). The issue arises from a logic error in the query messages route, where a message limit of zero is interpreted by the database as 'no limit'. This flaw allows a remote unauthenticated attacker to craft requests that download an entire channel's message history in a single, resource-intensive request. Additionally, attackers can send multiple such requests in parallel, causing significant resource exhaustion.

Impact

Exploitation of this vulnerability can lead to resource exhaustion, causing a denial-of-service condition on the affected system.

Remediation

Users are advised to upgrade to stoatchat version 20250210-1 (0.8.2) or later.

Added: Jul 16, 2026, 1:35 PM
Updated: Jul 16, 2026, 1:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.1
remediation
0.0
relevance
9.7
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.