CVE-2026-100674
Last modified
CVE-2026-100674 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists and length limits to create reserved-name lookalikes, embed special characters, and exceed the 32-character storage limit..
Description
stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists and length limits to create reserved-name lookalikes, embed special characters, and exceed the 32-character storage limit.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| stoatchat | stoatchat | < 0.15.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100674?
How severe is CVE-2026-100674?
How do I fix CVE-2026-100674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100669Grav before 2.0.25 ships web server configuration samples wh…7.5
- CVE-2026-10067A vulnerability was detected in Shibby Tomato 1.28. Impacted…8.8
- CVE-2026-100670Grav CMS 2.0.14 through 2.0.24 contains a privilege escalati…8.8
- CVE-2026-100671Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 —…8
- CVE-2026-100672The Comments plugin (getgrav/grav-plugin-comments) for Grav …7.5
- CVE-2026-100673The Grav Data Manager plugin (getgrav/grav-plugin-datamanage…8.2
- CVE-2026-100675stoatchat versions before 0.15.5 contain a denial of service…6.5
- CVE-2026-100676January, the media proxy/embed service of stoatchat (stoatch…8.2
- CVE-2026-100677stoatchat before 0.15.5 contains an account enumeration vuln…5.3
- CVE-2026-100678stoatchat before 0.15.5 fails to enforce account-level attem…6.5
- CVE-2026-100679stoatchat before 0.15.5 fails to validate that MFA tickets b…8.8
- CVE-2026-10068A flaw has been found in Shibby Tomato 1.28. The affected el…7.3
Are you affected by CVE-2026-100674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
