Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stoatchat
Stoatchat stoatchat |
|
| Vendors & Products |
Stoatchat
Stoatchat stoatchat |
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access. | |
| Title | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:23:40.935Z
Reserved: 2026-09-26T02:36:51.809Z
Link: CVE-2026-100678
No data.
Status : Received
Published: 2026-09-26T14:16:51.857
Modified: 2026-09-26T14:16:51.857
Link: CVE-2026-100678
No data.
OpenCVE Enrichment
Updated: 2026-09-26T18:15:08Z