{"id":"CVE-2025-71377","summary":"stoatchat before 20250210-1 Unrestricted Message History Fetch","details":"stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.","aliases":["GHSA-h7h6-7pxm-mc66"],"modified":"2026-08-12T03:51:33.547514423Z","published":"2026-07-16T12:19:14.582Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"0.8.2"}]}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-1025"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71377.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71377.json"},{"type":"ADVISORY","url":"https://github.com/stoatchat/stoatchat/security/advisories/GHSA-h7h6-7pxm-mc66"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71377"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/stoatchat-before-20250210-1-unrestricted-message-history-fetch"},{"type":"FIX","url":"https://github.com/stoatchat/stoatchat/commit/5f84daa9dba34c103cd83a2ee1f5e5ba900bfe94"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stoatchat/stoatchat","events":[{"introduced":"0"},{"fixed":"eb5f5f91cdd2eb37b4b99ed66b90887b8c6f4895"},{"fixed":"5f84daa9dba34c103cd83a2ee1f5e5ba900bfe94"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"20250210-1"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["20241227-2","20241227-1","20241226-1","20241222-6","20241222-5","20241222-4","20241222-3","20241222-2","20241222-1","20241220-1","20241213-1","20241212-1","20241128-3","20241128-2","20241128-1","20241024-1","20241002-7","20241002-6","20241002-5","20241002-4","20241002-3","20241002-2","20241002-1","20241001-1","20240929-3","20240929-2","20240929-1","20240909-2","20240909-1","20240830-1","20240829-3","20240829-2","20240829-1","20240805-1","20240710-1","20240629-1","20240626-1","20240625-2","20240625-1","20240623-1","20240621-1","20240620-2","20240620-1","20240619-1","20240615-1","20240611-3","20240611-2","20240611-1","20240609-1","20240604-1","20240516-1","20240408-4","20240408-3","20240408-2","20240408-1","20240407-1","20240212-1","20240210-2","20240210-1","20240206-1","20231028-2","20231028-1","20231026-01","20230905-1-beta","20230903-2-beta","20230903-1-beta","20230827-3-beta","20230827-2-beta","20230827-1-beta","20230826-1","20230810-3","20230810-2","20230810-1","20230704-1","20230702-1","20230615-1","20230611-5","20230611-4","20230611-3","20230611-2","20230611-1","20230604-1","20230603-3","20230603-2","20230603-1","20221119-1","20221023-2","20221023-1","20220918-2","20220918-1","20220912-1","20220903-1","20220902-1","20220901-1","20220814-1","20220726-1","20220718-1","20220715-1","0.5.5","20220714-1","20220710-1","0.5.4","20220623-1","20220621-1","20220620-1","20220614-1","20220612-4","20220612-3","20220612-2","20220612-1","20220611-1","20220610-2","20220610-1","20220609-1","20220606-1","0.5.3-5-patch.3","0.5.3-5-patch.2","0.5.3-5-patch.1","0.5.3-5","0.5.3-4","0.5.3-3","0.5.3-2","0.5.3-1","0.5.3-patch.2","0.5.3-patch.1","0.5.3","0.5.3-rc.5","0.5.3-rc.4","0.5.3-rc.3","0.5.3-rc.2","0.5.3-rc.1","0.5.3-alpha.16","0.5.3-alpha.15","0.5.3-alpha.14","0.5.3-alpha.13","0.5.3-alpha.11","0.5.3-alpha.10","0.5.3-alpha.9","0.5.3-alpha.8","0.5.3-alpha.7","0.5.3-alpha.6","0.5.0","0.4.1","0.4.0","0.3.3","0.3.3-alpha.7","0.3.3-alpha.6","0.3.3-alpha.5","0.3.3-alpha.4","0.3.3-alpha.3","0.3.3-alpha.2","0.3.3-alpha.1","0.3.3-alpha.0","0.3.2","0.3.1","0.3.0-rc.0","0.3.0","0.2.10","0.2.9","0.2.8","0.2.7","0.2.6","0.2.5","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71377.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}