CVE-2025-71377: stoatchat before 20250210-1 Unrestricted Message History Fetch
stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch requests to download an entire channel's message history in a single expensive request, and can send many such requests in parallel, resulting in denial of service through resource exhaustion.
Security readout for executives and security teams
Plain-English summary
CVE-2025-71377 lets an unauthenticated remote user force vulnerable stoatchat servers to return an entire channel history through one expensive message lookup. The main business risk is service disruption from resource exhaustion, with possible exposure of channel message history depending on deployment and access controls.
Executive priority
Prioritize remediation for internet-facing or unauthenticated stoatchat deployments. The issue is high severity because one unauthenticated actor may trigger service exhaustion, but public evidence of active exploitation is not provided.
Technical view
In stoatchat before 20250210-1 (0.8.2), the nearby-message query route can pass a zero limit to the database. The database treats that as unlimited, allowing full channel history retrieval and high-cost parallel requests. The CVSS 4.0 score is 8.7, driven by unauthenticated network denial-of-service impact.
Likely exposure
Exposure appears limited to organizations running stoatchat versions before 20250210-1 (0.8.2), especially deployments where the message query route is reachable by unauthenticated network users.
Exploitation context
The source bundle describes remote unauthenticated exploitation potential, but does not cite known in-the-wild exploitation. The CVE is not marked KEV. Treat exploit status as unconfirmed, not actively exploited.
Researcher notes
Key evidence is the vendor advisory, CVE record, VulnCheck advisory, and patch reference. The weakness is a limit-handling logic error, not memory corruption. Avoid assuming broader confidentiality impact beyond the described channel history retrieval.
Mitigation direction
Upgrade to the fixed stoatchat release identified by the vendor advisory.
Review the linked patch commit and vendor guidance before exposing affected routes.
Limit unauthenticated reachability to message history endpoints where operationally possible.
Monitor for unusually large or repeated nearby-message history requests.
Validation and detection
Inventory stoatchat deployments and confirm exact package or image versions.
Verify whether deployed versions are before 20250210-1 (0.8.2).
Check whether unauthenticated users can reach the message query route.
Review access logs for unusually large message-history responses or repeated parallel requests.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-1025: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-1025 · source CWE mapping
Comparison Using Wrong Factors
Comparison Using Wrong Factors represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.