CVE-2025-71377
CVE-2025-71377 is a high-severity vulnerability with a CVSS 4.0 base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1025.
Key facts
- Severity: High (CVSS 4.0 base score 8.7)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1025
- Published:
- Last modified:
Description
stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.
Frequently asked questions
- What is CVE-2025-71377?
- stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.
- How severe is CVE-2025-71377?
- CVE-2025-71377 has a CVSS 4.0 base score of 8.7, rated high severity.
- Is CVE-2025-71377 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2025-71377?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2025-71377 published?
- CVE-2025-71377 was published on 2026-07-16 and last updated on 2026-07-20.
References
- https://github.com/stoatchat/stoatchat/commit/5f84daa9dba34c103cd83a2ee1f5e5ba900bfe94
- https://github.com/stoatchat/stoatchat/security/advisories/GHSA-h7h6-7pxm-mc66
- https://www.vulncheck.com/advisories/stoatchat-before-20250210-1-unrestricted-message-history-fetch
Other CWE-1025 vulnerabilities
- CVE-2026-9800 — High (CVSS 8.1): A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all…
- CVE-2026-40880 — High (CVSS 8.1): ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a…
- CVE-2026-75840 — High (CVSS 7.5): ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist…
- CVE-2025-32464 — Medium (CVSS 6.8): HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow…
- CVE-2026-40227 — Medium (CVSS 6.2): In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map…
- CVE-2024-20342 — Medium (CVSS 5.8): Multiple Cisco products are affected by a vulnerability in the rate filtering feature of the Snort detection engine…